Hacker News new | ask | show | jobs
by eeZi 3535 days ago
> It's also the case that Debian accepts binary packages built on the developer's personal machine

Pretty common - many community distros do. Arch Linux too. Worrying for obvious reasons.

At least they're putting in an actual effort at making builds reproducible.