|
|
|
|
|
by prepperdev
1991 days ago
|
|
Debian policy is very sane (no network access during build), but it does seem like modern software just assumes that the Internet is always available, and all dependencies (including transitive) are out there. The assumption is a bit fragile, as proven by the the left-pad incident ([1]). I hope that whatever the outcome of the discussion in Debian will be, it would keep the basic policy in place: not relying on things outside of the immediate control during package builds. 1. https://evertpot.com/npm-revoke-breaks-the-build/ |
|
The world will keep turning.