-
Notifications
You must be signed in to change notification settings - Fork 50
Open
Description
Recommending that users clone the repo to have control over its content is not bad, but a security-conscious user should also care about any opaque files, such as packages or binaries. So:
Why are these files necessary?
Where do they come from?
How would one rebuild them?
Ideally we'd be able to do a reproducible build, producing byte-for-byte identical files, but setting that up is likely a lot of work.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels