What is Nostr?
LisPi /
npub1326…gzqx
2024-03-29 22:41:53
in reply to nevent1q…60p0

LisPi on Nostr: That is true. Binary artifacts have no business existing in Free Software (or ...

That is true.

Binary artifacts have no business existing in Free Software (or near-binary considering how auditable pre-generated config scripts end-up being). The way it was compromised in this case is almost certain to have happened before and reminds me of the SourceForge malware debacle (so arguably that's another famous example of it happening before).

I"m not sure if many other projects do like Guix and record the checksum of the whole repository so as to ensure reproducibility purely from source.
Author Public Key
npub1326y4p8mw4l750yc8e52n0xguvcl5j0dn88ul5r2gjva2sh2ay7qjqgzqx