Remix.run Logo
pshirshov 5 hours ago

But sorta possible to solve with source-based distribution and totally possible to solve with pure reproducible builds.

gertop 3 hours ago | parent | next [-]

It's entirely possible to ship malware in source form... Just look at the numerous supply chain attacks. Nix is a cute project but entirely irrelevant here.

miniBill 2 hours ago | parent [-]

It is possible but visible, and it means burning an identity, so it's not irrelevant

daveguy 5 hours ago | parent | prev [-]

What systems have pure reproducible builds? Does Nix? Any others? From what I understand, it is a very difficult problem.

pshirshov 4 hours ago | parent [-]

https://stal-ix.github.io/ and Guix, but the definitions of purity are different for them.

Yes, a very difficult problem, compilers must be pure functions with thin effectful wrappers.