@bagder idk what would be practical differences between these two systems and how one or the other would be more secure against supply chain attacks or other mitms
would be pretty interested in some reference materials
@bagder idk what would be practical differences between these two systems and how one or the other would be more secure against supply chain attacks or other mitms
would be pretty interested in some reference materials
@domdel maybe I want there at that time
quick search of "net install reproducible" yields only dotnet stuff
I'm not that knowledgeable about inside workings, but in theory (in my head) hashing all inputs does equate to byte-to-byte reproducibility, even if previous steps in the build process weren't written specifically to be reproduced
#nixos is somewhat of pioneer in the space of reproducible builds and is 20 years old
always measure only after everything is already build and billions are spent. vibe building, vibe accounting, vibe utilities