potiuk commented on PR #37:
URL: https://github.com/apache/tooling-actions/pull/37#issuecomment-5744261182

   > Also, reproducibility is a binary artifact concern and not a source 
concern. We already check that a source release exists in the repository at a 
declared revision/SHA matches since that is one of the extended checks voters 
should be doing.
   
   I think quite the opposite - it would alleviate easily all the complaints 
about "do not know what you are checking". Perfect reproducibility of the 
source artifacts that are published in ATR and ones that PMC can generate 
locally is the only **real** way for the PMC to know what they are voting on - 
this for example would **completely** invalidate any issues that Sebb raised 
before - because the PMC could use reproducibility check to know that Release 
manager did not modify uploaded source artitcat.
   
   Which is exactly the scenario that 'xz` issue hed. The release manager 
modified the .tar.gz artifact  - it was not produced  from the specific commit 
- it has few lines injected. And reproducibility check by independent PMC 
members -> recreating the same .tar.gz file is the **fastest** and most certain 
way to verify that release manager preparing the artifact was not roque, 
blackmailed, or that someone stole their credentials and wanted to inject stuff.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to