git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* criteria for linking to binaries from git-scm.com?
@ 2023-04-12  8:00 Jeff King
  2023-04-13  0:26 ` brian m. carlson
  0 siblings, 1 reply; 3+ messages in thread
From: Jeff King @ 2023-04-12  8:00 UTC (permalink / raw)
  To: git

There's an interesting question raised in an issue in the git-scm.com
repo that I think would benefit from input from community folks here.

The link is:

  https://github.com/git/git-scm.com/issues/1774#issuecomment-1504829495

but the tl;dr is:

  From a supply chain perspective, what are our criteria for linking to
  a third party's pre-built binaries from git-scm.com?

Obviously we don't want to point people at malicious or trojaned
binaries. But we probably also bear some responsibility for making sure
the third party has reasonable security practices themselves.

I don't have a strong opinion myself, and this is probably a giant can
of worms. But it seemed like the kind of thing that should be getting
attention from the greater community, and not just languishing in that
repo (both to set a policy for new requests, but also maybe to evaluate
existing binaries we point to).

-Peff

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2023-04-13 13:44 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-04-12  8:00 criteria for linking to binaries from git-scm.com? Jeff King
2023-04-13  0:26 ` brian m. carlson
2023-04-13 13:43   ` Derrick Stolee

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).