> we could add a feature to freight where the package.json specifies the sha256 hash of the freight bundle, and rejects a bundle that doesn't match