A small step for debian, giant leap for mankind.
Debian must ship reproducible packages
11–20 of 178 posts
Re: Debian must ship reproducible packages
#12zero improvement on end-user experience. does not solve supply chain issues, debian package will reproducabily contain the malware from upstream.
Reproducable builds are not solving all issues as you rightly observed, but they can be a stepping stone (or even a pre-condition) for further measures.
Re: Debian must ship reproducible packages
#13zero improvement on end-user experience. does not solve supply chain issues, debian package will reproducabily contain the malware from upstream.
> zero improvement on end-user experience. Maybe not by itself, but it does allow for the ecosystem to be audited, in a way that ultimately benefits the end-user. It really is an important part of a healthy supply chain.
Re: Debian must ship reproducible packages
#14Re: Debian must ship reproducible packages
#15Re: Debian must ship reproducible packages
#16zero improvement on end-user experience. does not solve supply chain issues, debian package will reproducabily contain the malware from upstream.
It does not solve all supply chain issues, it do solve some supply chain issues. Not being able to see if the source code shipped is the same as been used for creating the binary is scary
Re: Debian must ship reproducible packages
#17Good thing. NetBSD has fully reproductible build since 2017. https://blog.netbsd.org/tnf/entry/netbsd_fully_reproducible_...
BTW, most Debian packages have reproducible builds. Those which have not (I'd say 5%) are shown in orange in the graph there: https://wiki.debian.org/ReproducibleBuilds
Re: Debian must ship reproducible packages
#18Earlier quoted context omitted.
> zero improvement on end-user experience. Maybe not by itself, but it does allow for the ecosystem to be audited, in a way that ultimately benefits the end-user. It really is an important part of a healthy supply chain.
[flagged]
Re: Debian must ship reproducible packages
#19Re: Debian must ship reproducible packages
#20Earlier quoted context omitted.
Debian has had a better "software supply chain" posture than any other player in the ecosystem since before the turn of the century. While we all face the risk of malware from upstream, Debian is the least at risk of being affected by it. See for example the stream of issues from npm et al. None of it has affected Debian.
> for example the stream of issues from npm et al. Curious, what distros where affected by npm supply chain attacks?