Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How does guix fix the trusting trust attack?

Aside: I wonder if AI code inspection and review could be put in place to detect xz-like malicious changes to the supply chain for major distros.



https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-...

Guix bootstraps (in 2023, no clue about now) from a 357-byte program. You audit the bytecode.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: