!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

532 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30118 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
11 May 2023
@raitobezarius:matrix.orgraitobezariusWould you be interesting into getting that hash collection infra first?17:14:58
@raitobezarius:matrix.orgraitobezariusThen we can build Trustix on the top of that IMHO17:15:02
@julienmalka:matrix.orgJulienI would need to read more on what you mean by "hash collection infra"17:15:30
@raitobezarius:matrix.orgraitobezariusGo to Security Discussion17:15:39
@raitobezarius:matrix.orgraitobezariusThere's a bit of discussion there17:15:44
@raitobezarius:matrix.orgraitobezariusExpanding what it is17:15:50
@julienmalka:matrix.orgJulienBut yes, it fits my research interests to help nix get better in terms of software supply chain security17:16:00
@julienmalka:matrix.orgJulien
In reply to @raitobezarius:matrix.org
Go to Security Discussion
Sure, but each time I join a new matrix channel I get a little bit more sick
17:16:35
@raitobezarius:matrix.orgraitobezariusdon't worry I will do a RFC for IRC17:16:44
@julienmalka:matrix.orgJulienWhere should I sign ?17:17:06
@julienmalka:matrix.orgJulienAh yes, the "hash collection infra" looks like something I had in mind actually 17:19:08
@julienmalka:matrix.orgJulienWell I'd be ready to work on that kind of solution and could probably even have that be part of my PhD when I start it17:20:22
@raitobezarius:matrix.orgraitobezariusstop giving hope to this channel's people17:20:55
@davidak:matrix.orgdavidak
In reply to @raitobezarius:matrix.org
Would you be interesting into getting that hash collection infra first?

i think trustix has hash collection infra, but no one knows if and how it works (except adisbladis who is unresponsive to the questions)

https://github.com/nix-community/trustix/issues/90

19:36:58
@davidak:matrix.orgdavidaki have collected thousands of hashes on my computer from reviewing PRs and would like to share them, so we can get a broader picture of unreproducible packages19:41:11
@raitobezarius:matrix.orgraitobezariusSomeone needs to investigate this properly19:53:20

Show newer messages


Back to Room ListRoom Version: 6