hackage, cabal-get, and security

it seems like we search for a BIG solution for a small problem :)

for automatically downloading of libraries used in some software - all
we need is to know that we download library released by the same
person who release the original library used to construct this
software. it is no matter whether he was a Jesus Christ or Ben Laden
or anyone else :)

may be it's better to drop all the like-the-supermans games and follow
the Task -> Requirements -> Solution path?

