|
|
|
|
|
by dvogel
38 days ago
|
|
(Not OP, but...) I still fail to see the current value in confirming that a reproducing builder also included the same compromised dependency that I did when I built it. I understand that reproducible builds are guarding against dynamic attacks within build infrastructure. However I just don't see those happening. Compromised source dependencies are a 100x more common problem. |
|
Another thing to consider is that Debian has quite a few derivatives who may also rebuild packages from source, so you have a multiplier there.