Elektrine lite

← Feed

@civodul@toot.aquilenet.fr

Post #1669965

2026-04-21 14:30 UTC

@raito Compromised forges are not a problem: one needs access to a committer’s key to get code in Guix. Coercion? The only way I can think of to mitigate this is canaries. But this is hard to counter by definition, and I’d say beyond our threat model (for now). @zimoun @luj

Replies (2)

  • @raito@nixos.paris 2026-04-21 14:31

    @civodul @zimoun @luj Compromised committer laptops I meant.

    Open ##1669966

  • @raito@nixos.paris 2026-04-21 14:31

    @civodul @zimoun @luj For Nixpkgs, I think this is not, alas, out of the scope. People run many workloads at the same time, it's very easy to do `npm install worm` on one window and have it lateralize their access to a commit bit.

    Open ##1669967