potiuk commented on PR #37: URL: https://github.com/apache/tooling-actions/pull/37#issuecomment-5744261182
> Also, reproducibility is a binary artifact concern and not a source concern. We already check that a source release exists in the repository at a declared revision/SHA matches since that is one of the extended checks voters should be doing. I think quite the opposite - it would alleviate easily all the complaints about "do not know what you are checking". Perfect reproducibility of the source artifacts that are published in ATR and ones that PMC can generate locally is the only **real** way for the PMC to know what they are voting on - this for example would **completely** invalidate any issues that Sebb raised before - because the PMC could use reproducibility check to know that Release manager did not modify uploaded source artitcat. Which is exactly the scenario that 'xz` issue hed. The release manager modified the .tar.gz artifact - it was not produced from the specific commit - it has few lines injected. And reproducibility check by independent PMC members -> recreating the same .tar.gz file is the **fastest** and most certain way to verify that release manager preparing the artifact was not roque, blackmailed, or that someone stole their credentials and wanted to inject stuff. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
