stackmuncher / stm_app

This software engineer profile builder turns your code into a detailed list of skills for an online directory of software developers.
https://stackmuncher.com
GNU Affero General Public License v3.0
22 stars 1 forks source link

Biuld reproducibility #14

Open rimutaka opened 3 years ago

rimutaka commented 3 years ago

How do we know that there are no vulnerabilities or backdoors introduced into the build via dependencies?

rimutaka commented 3 years ago

Looks like checking in Cargo.lock should solve the problem. Full response on reddit: https://www.reddit.com/r/rust/comments/ofurfs/how_to_achieve_identical_compilations_of_the_same/h4eznav/?utm_source=reddit&utm_medium=web2x&context=3