Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The fact that the source code is available does not guarantee that the blob is the product of that source.


This is why there is the "Reproducible Builds"[0] initiative from Debian folks.

[0] https://reproducible-builds.org/


That's true and, to me, has been brought on the spotlight from Microsoft practices around VSCode. On the other hand, for an OSS project, building the binary is not that hard.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: