5 ms·
Assuming you're not pulling in software from outside of nixpkgs, Yes.
by Krutonium 4mo ago
Assuming you're not pulling in software from outside of nixpkgs, Yes.
- lostmsu 4mo agoWhy? AFAIK original source is never reviewed, only the change in nixpkgs. So if the original is compromised, the malware will make it to nixpkgs.
- Krutonium 3mo agoThe scope of nixpkgs is nixpkgs. If every package's entire source code was being audited, then there is no such thing as a sustainable repository of software. There simply isn't enough people, or money for AI, to do it.
- lostmsu 3mo ago> or money for AI, to do it. OpenAI and Anthropic both provide free credits for OSS. Smaller models feasibly can review every commit IMO. Would not be cheap for sure, but also would probably be cheaper than a single fulltime employee.
- Krutonium 3mo agoThis would amount to auditing the vast majority of open source code found on the Internet. Not even OpenAI or Anthropic seem quite interested in doing that.