3 ms·
With hindsight it's not the runtime behaviour of the library that you'd want to test - the weakest point in the chain is where the distributed source .tar.gz ca
by caf 2y ago
With hindsight it's not the runtime behaviour of the library that you'd want to test - the weakest point in the chain is where the distributed source .tar.gz can't be regenerated from the project repository.
- josephg 2y agoFor how many projects is that actually checked? I bet barely any. Its especially difficult because most projects aren't built in a reproducible way. You should be able to uncompress and compare a source tarball. But if you get a binary and the source code used to generated that binary, there's no way to tell that they match.
- caf 2y agoLuckily the source tarball is the more important one to check, because that's the difference between backdooring one distribution and backdooring them all. It's still not trivial because there might well be legitimate processing steps that are used to create the tarball, but it should be doable.