Hacker News new | ask | show | jobs
by CuriousCosmic 1235 days ago
Worth considering using nix with cargo. Of course it still involves a lot of "download from github" or "download from nix cache" but reproducibility + tight source hash pinning helps guarantee provenance.