3 ms·
I don't follow. The NARs are signed by a key that (presumably?) only Hydra has access to. (The signature is then recorded in the narinfo file). The integrity is
by predictabl3 3y ago
I don't follow. The NARs are signed by a key that (presumably?) only Hydra has access to. (The signature is then recorded in the narinfo file). The integrity is the nixpkgs history, and the signature verification that happens when you pull the narinfo+NAR from a cache that hydra pushed to.
- lrvick 3y agoHow can Hydra know the nixpkgs repo was not tampered with? Maintainers impersonated? How can anyone know the Hydra signing key was not tampered with? These are problems other linux distros have solved for decades by just requiring maintainers press a blinking yubikey or similar to sign their contributions.