5 ms·
> nixpkgs packages pretty much everything I need. Yeah, because they allow anyone to contribute with little oversight. As Lance Vick wrote[1], "Nixpkgs is the
by subsection1h 1y ago
> nixpkgs packages pretty much everything I need.
Yeah, because they allow anyone to contribute with little oversight. As Lance Vick wrote[1], "Nixpkgs is the NPM of Linux." And Solène Rapenne wrote[2], "It is quite easy to get nixpkgs commit access, a supply chain attack would be easy to achieve in my opinion: there are so many commits done that it is impossible for a trustable group to review everything, and there are too many contributors to be sure they are all trustable."
[1] https://news.ycombinator.com/item?id=34105784 https://news.ycombinator.com/item?id=34105784
[2] https://web.archive.org/web/20240429013622/https://dataswamp.org/~solene/2024-04-27-nix-internal-crisis.html https://web.archive.org/web/20240429013622/https://dataswamp...
- microtonal 1y agoPretty much every PR does get reviewed before merging (especially of non-committers) and compromises would be easy to detect in the typical version bump PR. At least it's all out in the open in a big monorepo. E.g. in Debian, maintainers could push binaries directly to the archive a few years ago (I think this is still true for non-main) and IIRC even for source packages people upload them with little oversight and they are not all in open version control. Of course, Debian developers/maintainers are vetted more. But an intentional compromise in nixpkgs would be much more visible than in Debian, NPM, PyPI or crates.io.