|
|
|
|
|
by mikemcquaid
2722 days ago
|
|
Almost everything we have is open for you to examine (including the code, obviously). If you're not willing or able to do that: yes, you have to trust us (like you do with pretty much all software and infrastructure you don't personally control). |
|
It is frustrating that you are being so opaque and dismissive. You still haven't answered my earlier question if the Homebrew project has published a summary of the results of these security reviews (I understand not posting the entire review publicly). A quick Google search did not turn up anything, which is why I am asking.
For contrast: I can find out the build process for a Debian package from their website[1]. While they do have some private operation documentation, they also publish the process by which packages get pulled into their system, built, and pushed to the mirrors[2][3]. They have documentation for how to replicate their build environment and build packages on my own[4]. This documentation is open, and I can verify packages with it as they move toward reproducible builds[5]. I understand that Debian is a much larger operation with a much longer history. I understand that it takes time to develop these things. This is not an attack on the Homebrew project or the work they do.
[1] https://www.debian.org/devel/buildd/
[2] https://www.debian.org/devel/buildd/operation
[3] https://wiki.debian.org/Teams/FTPMaster
[4] https://wiki.debian.org/BuilddSetup
[5] https://wiki.debian.org/ReproducibleBuilds