Post #1669959
2026-04-17 13:19 UTC
Replies (2)
-
@zimoun@social.sciences.re 2026-04-17 15:16
@raito Indeed there is often a mismatch between what users expect and tools tackle. I think, both Guix and Nix, are often “unclear” on this topic. Somehow, reproducible builds is maybe not the first wagon about supply chain security. Moreover, about Guix and supply chain security, I sometimes feel the same situation as 42 long and complex password written on a piece of paper close to the keyboard. 😉 @luj
-
@civodul@toot.aquilenet.fr 2026-04-20 20:20
@raito Supply chain security has been addressed from different angles in Guix, which I tried to explain in https://doi.org/10.22152/programming-journal.org/2023/7/1 Probably not the end of the story (we’re still tackling sometimes ridiculous issues, like avoiding “source” tarballs that contain pre-built artifacts), but a good start. @luj @zimoun