I find it a bit weird how reflections on trusting trust is being forced into these discussions, almost like it's a solved problem. But it very much isn't, and existing distro toolchains are still very opaque.
@aeva The repository handling scripts in Arch Linux is around 20 years old now. Rewritten twice over three different VCS tools.
It's also been developed in cvs, SVN and git, and the all the history is preserved!
I have several times run the git log looking at the 20 year old code wondering how they did stuff way back when to make sense of current repo handling.
F/OSS Hacker. Arch Linux Developer, Security Team, Reproducible Builds. General Linux stuff and supply chain issues.Writes in English and Norwegian from time to time.He/Him