4 ms·
As a maintainer of open source libraries, the steps I've been asked to take to secure the supply chain are: * Signing releases (requested by linux distribution
by tlocke 4y ago
As a maintainer of open source libraries, the steps I've been asked to take to secure the supply chain are:
* Signing releases (requested by linux distributions)
* Signing commits (actually I don't think anyone actually asked me to do that)
* Authenticating myself with a physical security key. (requested by PyPI)
I found these things easy to automate and they seemed worthwhile to do, and so I don't resent doing them. My sense is that these things are being gradually built in to tools and will become the default without any effort on the part of library maintainers.
So hopefully you'll allow me to sneak in another point! Open source licences create relationships that in political theory would be called anarchism. In software anarchy, anyone's allowed to do anything (or not do anything) they like with their copy of the code. Software is what economists call a non-rivalrous good (ie, multiple people can enjoy it without affecting each other). Anarchy works well with non-rivalrous goods. In contrast, businesses are built around rivalrous goods (ie if you have it, I can't have it), and in this world anarchy doesn't work, and you have to view things through contracts and money.
I think I'll stop there :-)
- _nalply 4y agoI agree with the term "anarchy" as long as other people don't take my human rights away.
- senko 4y ago> Authenticating myself with a physical security key. (requested by PyPI) Is that only for some packages? I publish a few obscure ones (not widely used) and get away with just a password.
- Semaphor 4y agoTop 1% get them for free and have to use them from my undrstanding: https://portswigger.net/daily-swig/pypi-repo-to-distribute-4-000-security-keys-to-maintainers-of-critical-projects-in-2fa-drive https://portswigger.net/daily-swig/pypi-repo-to-distribute-4...
- hardolaf 4y agoWhat if the maintainers just say no?
- Conan_Kudo 4y agoWell, PyPI would be in a very bad place, because they can't force them to say "yes". But they've backed themselves into a corner by punishing people for making software that becomes popular. :/
- tlocke 4y agoAs I recall it's mandatory. I can see the package indexes becoming much more involved in supply chain issues. A bit like the app stores, where a considerable amount of vetting goes on.
- senko 4y agoThat's an interesting idea! A "vetted" package index that charges subscription and splits the revenue with package maintainers. In return, maintainers agree to jump through all the extra hoops and index maintainers do extra verification (but still no warranty except that the standard procedure is followed). The same package can then be uploaded to the normal index (as it is now), but without these extra steps, and no vetting.
- daitangio 4y agoInteresting point indeed. It remembers me the Raymond’s “The Cathedral and the Bazaar” book. As a consultant my work is ro take care of the software I produce and use.