3 ms·
I’m sure reproducible builds has some small part to play in supply chain security, but I think it is massively over-emphasised. My own view is that all of supp
by nmadden 5y ago
I’m sure reproducible builds has some small part to play in supply chain security, but I think it is massively over-emphasised.
My own view is that all of supply chain security is somewhat of a red herring anyway. I don’t want to have to trust software vendors at all, whether I think they may have been hacked or not. I shouldn’t have to trust log4j or any other legitimate dependency. And I shouldn’t have to audit the source code (or delegate that) to find out if I should trust it. We run all software with far too many privileges by default. Kate Sills at Agoric had a great article about this a few years back (Medium, sorry): https://medium.com/agoric/pola-would-have-prevented-the-event-stream-incident-45653ecbda99 https://medium.com/agoric/pola-would-have-prevented-the-even...