Hacker News new | ask | show | jobs
by _bin_ 619 days ago
Assuming you trust Github, of course. I think if someone is seriously worried code has been altered between source and maintainer-provided binary, his big concern will be the time it takes to audit the source code (which he also shouldn't trust). The build time will be inconsequential next to that.
1 comments

The Reproducible Builds project is working on trustworthy builds:

https://reproducible-builds.org/