Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not at all. Pulling sources, reviewing and vetting them and finally building are completely different steps.

Linux package maintainers do the vetting. Buildbots build in a clean room environment, without Internet access.

If you mix up the steps supply chain security is gone.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: