!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

545 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30125 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
28 May 2025
@emilazy:matrix.orgemilyah, I see :)02:04:44
@emilazy:matrix.orgemily but you don't need to go back more than a few weeks for staging-next to mean no built packages before then would end up in the closure? 02:05:16
@emilazy:matrix.orgemily(ignoring FODs)02:05:19
@emilazy:matrix.orgemilyworld rebuilds happen a lot more than every half-decade02:05:28
@raboof:matrix.orgraboof emily: starting from an old image reduces the attack surface for supply chain attacks somewhat: an attacker would've had to infect either the 20.03 image or one of a narrower set of more recent packages. but I agree it's somewhat in the 'long tail' of concerns :) 06:37:26
@emilazy:matrix.orgemilybecause even though it "adds" the risk of vulnerabilities in 20.03 producing incorrect results, one can presume that such an elaborate backdoor would have infected the bootstrap tarballs since then? fair enough11:16:47

Show newer messages


Back to Room ListRoom Version: 6