conda-forge / conda-forge/conda-forge.github.io

Support reproducible builds to automate security auditing of binary artifacts

オープン
#1,915 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
question
主要言語
JavaScript
スター
170
フォーク
320
平均マージ
2日 10時間
マージ済み PR(30日)
5

説明

### Your question:

Has the conda-forge project any plans to make (some of) the builds [byte-for-byte reproducible](https://reproducible-builds.org)?

And if so (or if they already are in some cases) has the project plans for documenting or developing some tooling to automatically re-build and compare the checksum for packages potentially impacted by a security breach of one of the infrastructure providers (e.g. a CI provider) [as recently happened with Circle CI](https://conda-forge.org/blog/posts/2023-03-12-circle-ci-security-breach/)?

The auditing of packages with reproducible builds could be triggered manually after specific security breach events.

It could also happen continuously (at least for the most popular packages to save CI costs), by running on different CI providers (for the most common CPU architectures) to have them cross-validate one another to be able to check that not any of them is corrupting the generated binary artifacts with a malware infected compiler for instance.

Note that, under Linux, the docker image itself should ideally be made reproducible to be able to check that it has not been tempered with. For Operating Systems without docker... I don't know what to do beyond trusting that different CI providers do not share tempered compilers and system libraries.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。