GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    LisPi (lispi314@udongein.xyz)'s status on Monday, 01-Apr-2024 10:12:02 JSTLisPiLisPi
    in reply to
    • Glyph
    • 🍒🌳 Hartmut Goebel
    • AndresFreundTec
    @kirschwipfel @glyph @AndresFreundTec > If the packager chooses to use the official tarball as "the source", validating the checksum would not have helped. :-(

    Unfortunately, yeah.

    > Also whether it's always possible to run running autoreconf depends on the content of the tarball.

    Of course if it isn't a C project then it probably isn't. If it is such a project, then one should have such tooling installed.

    > Which brings me to the (preliminary) conclusion that we'd better use repos as source of trust

    That is more sensible generally, as the history of an object and its belonging to a project is a reified (and verifiable) relationship under code versioning sytems, unlike arbitrary buckets of files.
    In conversationabout a year ago from udongein.xyzpermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.