Post #1434875
2023-01-01 19:50 UTC
@juandesant @foosel I would agree, but note that here I am not talking about this, I am talking of the push to "make secure" the supply chain, by asking the maintainers to use 2FA, make their build reproducible, etc. Some of this come not from the users but straight from government
Replies (1)
-
@juandesant@astrodon.social 2023-01-01 20:02
@Di4na @foosel oh, I had not understood that, I was thinking of more general principles… and it never occurred to me that someone else could think otherwise. At #SKAO we were creating our own images and repositories for dependencies, with their own security setups, because we understood we could not force that upstream.