[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
|
|
Subscribe / Log in / New account

Builds on GitHub instead of compromised developer machine

Builds on GitHub instead of compromised developer machine

Posted Oct 23, 2024 8:13 UTC (Wed) by farnz (subscriber, #17727)
In reply to: Insecure dev machines. by LtWorf
Parent article: Python PGP proposal poses packaging puzzles

On the assumption that you trust GitHub, this guarantees you that the source visible on GitHub is the corresponding source for the binary built on GitHub. With a developer doing the signing, I can build a binary that does not correspond to the given source, sign it, and upload it.

Reproducible builds would, of course, be better.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds