!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

544 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30124 Servers

Load older messages


SenderMessageTime
8 Oct 2021
@baloo_:matrix.orgbaloo1449 out of 1517 (95.52%) paths in the nixos.iso_minimal.x86_64-linux installation image are reproducible!18:28:24
@baloo_:matrix.orgbaloookay, same thing then18:28:31
@baloo_:matrix.orgbalooho, for ea4524e6cc7761c3cc271233fa97b5e7473f760a18:28:39
@baloo_:matrix.orgbaloostill a couple hundred commits behind :(18:28:47
@baloo_:matrix.orgbalooso that's without my fix18:28:55
@tomberek:matrix.orgtomberekyeah, we can just hard-bump nix in the repo? one sec18:41:10
@baloo_:matrix.orgbalooit's fixed on nixpkgs master18:43:11
9 Oct 2021
@baloo_:matrix.orgbaloo back at 100% \o/ 16:53:31
@trofi:matrix.org@trofi:matrix.org \o/ 17:15:14
@tomberek:matrix.orgtomberekWoohooo!17:19:22
12 Oct 2021
@wizeman:matrix.orgwizeman joined the room.01:42:06
@eordano:matrix.orgeordano joined the room.10:07:46
13 Oct 2021
@rch:matrix.orgrch joined the room.18:41:24
@baloo_:matrix.orgbaloo"openssf annonces $10m for investment in software supply chain"21:55:19
@baloo_:matrix.orgbaloonice of them to invest that much money in nix wow21:55:30
14 Oct 2021
@j-k:matrix.orgj-kimage.png
Download image.png
09:09:24
@j-k:matrix.orgj-kimage.png
Download image.png
09:09:41
@j-k:matrix.orgj-k Its 10mil funding to the OpenSSF from industry, for the above 09:10:07
@j-k:matrix.orgj-kAnd that's ignoring the thousands of dollars that have already gone into PyPI to upgrade their platform and implement TheUpdateFramework practices09:10:50
@j-k:matrix.orgj-kWhy is there interest now? Big high profile breaches month after month09:11:21
@j-k:matrix.orgj-kimage.png
Download image.png
09:11:24
@j-k:matrix.orgj-k

nice of them to invest that much money in nix wow

That's a funny comment but it's also really painful to read

FYI people involved in the Supply Chain Security part of the CNCF Security TAG and the SLSA framework are actually trying multiple times to reach out to the nix community in Discorse and Matrix but it gets f*ck all traction
One person showed interest and joined the channel to discuss SLSA and where nix as-is destroys requirements and pain points with ease

Jean-Paul in both the Dev and Security channels was asking if it was a good idea to put nixpkgs forward for a potential pro-bono security audit at their employer and again f*ck all interest

Then later on we start wondering, where's the funding, where's the adoption? Why is there a massive wave of interest in Supply Chain but they're building from scratch? Why aren't they learning off the OVER 10 years of work around nix/nixpkgs

09:11:50
@j-k:matrix.orgj-kimage.png
Download image.png
09:12:08
@j-k:matrix.orgj-khttps://matrix.to/#/#nix-slsa:matrix.org09:12:28
@j-k:matrix.orgj-khttps://github.com/slsa-framework/slsa/issues/156#issuecomment-93013672309:13:00
@j-k:matrix.orgj-kThe nix/nixos project is consistently high in graphs covering activity of opensource projects but even with all this supply chain focus, very little attention is going to nix It was even in the background in the keynotes.09:15:54
@j-k:matrix.orgj-kimage.png
Download image.png
09:15:59
@qyliss:fairydust.spaceAlyssa Rossj-k: do you have a link to the discourse discussion?09:19:32
@qyliss:fairydust.spaceAlyssa Rosssad that I've missed this09:19:37
@j-k:matrix.orgj-khttps://discourse.nixos.org/t/generating-software-bill-of-materials-from-derivation/1408909:19:54

Show newer messages


Back to Room ListRoom Version: 6