3 ms·
With that rationale, why not use https://github.com/go-acme/lego https://github.com/go-acme/lego which is a self contained lets encrypt client in Go?
by nullify88 2y ago
With that rationale, why not use https://github.com/go-acme/lego https://github.com/go-acme/lego which is a self contained lets encrypt client in Go?
- lrvick 2y agoStatic binary, sure, but hardly a tiny supply chain attack surface: https://github.com/go-acme/lego/blob/master/go.sum https://github.com/go-acme/lego/blob/master/go.sum Also their official builds are built with Alpine which is a hobby distro that does not even do signed code or packages.
- chrisweekly 2y agoAre you saying that any use of Alpine is, by definition, a supply-chain security problem?
- lrvick 2y agoI am, yes. Alpine is not full-source-bootstrapped, often imports and trusts external binaries blindly, has no signed commits, no signed reviews, no signed packages, and is not reproducible. It is one phished git account away from a major supply chain attack any day now. Alpine chooses low security for low contribution friction. It is the Wikipedia of Linux distros, which granted it a huge package repository fantastic for experimental use and reference, but it is not something sane to blindly trust the latest packages of in production. It is one of the reasons why I made stagex, which in most cases is a near drop-in replacement. https://codeberg.org/stagex/stagex https://codeberg.org/stagex/stagex
- chrisweekly 2y agoThanks for the detailed response! EDIT: Also, stagex looks pretty compelling; I hope it catches on!