6 ms·
Well, you'll always have to trust some point on being immutable. A git repository can mutate, but so can a central registry or a proxy. Once a version is cache
by strkek 9y ago
Well, you'll always have to trust some point on being immutable.
A git repository can mutate, but so can a central registry or a proxy. Once a version is cached in a registry or a proxy, nothing stops people with enough privileges from modifying that cached version.
So really the only thing that changes is just who you trust.
- Keats 9y agocrates.io is immutable, you can't edit/delete published versions. And npm is as well finally. > So really the only thing that changes is just who you trust. With an immutable central registry, I only need to trust the organization running it. Without it, my build depends on the maintainers of all my dependencies (including transitive) to build. In the case of Go that would be trusting Google versus trusting an unknown number of random persons. Even recently in Go there was this event: https://www.reddit.com/r/golang/comments/7vv9zz/popular_lib_gobindata_removed_from_github_or_why/ https://www.reddit.com/r/golang/comments/7vv9zz/popular_lib_... where someone deleted their account and someone else signed up and created another repository with the same name. I believe the Minimal Version System will ensure that no one gets automatically updated to a new version of potentially bad code there though.
- zbentley 9y agoIf you want an artifact repository for Go, several exist with varying levels of immutability/reliability/etc. However, Go also has an answer to the situation of "I want dependencies directly from the community without a caching/authorizing intermediary, but don't want to be a victim of someone rewriting their history on GitHub/account-squatting/whatever", and that answer is vendoring plus checking diffs on package upgrade. That's often less convenient than using a trustable caching registry, but it's comparing apples and oranges: a cache like that requires a centralized solution at present, though usable distributed ones might come about at some point; vendoring just requires some of your disk space and a git clone.
- reggieband 9y ago> nothing stops people with enough privileges from modifying that cached version They may be able to modify it but with some kind of trusted hash at least I'll know about it. Making a change to a repo that keeps the same version and also keeps the same hash is a more difficult attack to pull off.
- sseth 9y agoPlease see : https://research.swtch.com/vgo-repro https://research.swtch.com/vgo-repro - reproducible, verifiable builds. The same thing is possible in vgo, with planned support for hashes.
- ngrilly 9y agoYou can commit a go.modverify file in your project which contains a digest of each module used in the project.