3 ms·
No I think that's a perfect example of why this doesn't work. Once you remove the build tool from the assumed-impenetrable GitHub, where are your guarantees of
by ris 5y ago
No I think that's a perfect example of why this doesn't work. Once you remove the build tool from the assumed-impenetrable GitHub, where are your guarantees of non-tamperability for it? How is what you have now not "just" another build tool?
- skybrian 5y agoGitHub Actions is somewhat trustworthy, and other people can verify that it's doing the right thing by comparing results. If enough other people vouch for a build (and I don't think you need that many), you don't need to do it yourself. This doesn't seem all that different from how certificate transparency helps to build trust in DNS registries. Can you trust them to do their jobs? Well, it helps that if they do certain things wrong, someone will notice.
- ris 5y ago> and other people can verify that it's doing the right thing by comparing results You're essentially describing the solution I outlined in my original post. What is the proposal in this article actually adding that's not painfully obvious?
- skybrian 5y agoApparently they have an implementation making GitHub Actions one of the parties that's providing results to compare. I don't know how novel that is, but it seems useful?