5 ms·
What does this mean? Arm was using GitHub for source code hosting. But most of the new core infrastructure that Arm is deploying is on proprietary hardware, an
by fourthark 4y ago
What does this mean?
Arm was using GitHub for source code hosting. But most of the new core infrastructure that Arm is deploying is on proprietary hardware, and "GitHub is a black box and so we would have to work with them or let them do the work, and it wouldn't necessarily be correct," Wafaa says. "Then we'd have to do reviews. We wouldn't necessarily be able to do the patch reviews because it's all private and proprietary code… that was a big factor for us choosing GitLab."
Seems garbled, what does the proprietary nature of GitHub have to do with code review process?
Are they just saying they can’t host a lot of the code publicly?
- martinald 4y agoI think they are referring to on premesis GitHub Enterprise Server, which won't work for them because they are using new CPU archs like arm64 which it doesn't run on? That's my guess but not very clear at all...
- 3boll 4y agoIMHO they are talking about reviewing 3rd party software, not their own developments. But is not a great reason they probably have more products where the source is not available to them...
- lucideer 4y agoI would guess they're likely referring to the proprietary / black-box nature of (one of or a combination of) the Github API for automation tasks, the Github Apps marketplace & associated APIs, and the Github actions infra & archs.
- als0 4y agoYeah I’m sure this is garbled by a VP. Sounds like they want more control over the CI process and keep more of that process private.
- masklinn 4y agoI’d think it’s issues like CI runners and the like? I don’t think you can handroll github dedicated runners (e.g. I read recently that there’s still no support for M1 dedicated runners). If ARM wants to run CI directly on the ISAs they’re developing, or with complicated custom toolchains such that they can run tests on ISA under development from a host machine, they probably need pretty extensive customisations on the runner site, which would require contracting github to do that for them, or having to work directly on github code, for ARM-exclusive needs. Either way a lot of collaboration work for something which isn’t really collaborative, or of any concern or value to github as a company. And with possible risks of information leak one way or another.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- viccuad 4y agopart of the supply chain is your source forge and builders. On GitHub, you can point the builders to your own infra.. and then maybe check cryptographically that all source code that lands on the builder is correctly signed and trusted. But it's nearly impossible to do that for the forge itself (GitHub). I recommend https://slsa.dev https://slsa.dev (vendor-neutral effort from the Linux Foundation) for a better picture of a secure supply chain.
- fartcannon 4y agoHe's saying Microsoft can spy on your stuff and that they dont want that.
- renewiltord 4y agoPretty easy to understand if you have the context. They're probably using Github Enterprise (GHE). GHE may not run on their proprietary hardware. When things fail, they can't fix it because they don't have access to the source. When there is an update, they need to review the patches to make sure that stuff will work on their hardware. Simply put, the open source is a beneficial thing for Arm here.