We've been entertaining ideas to this direction before the xz incident, eg 
#2985 (for read-only source) and #2989. Read-only buildroot would be a logical 
extension of this. Some of these things are stepping into "mock territory", but 
then people still *do* run rpmbuild through other means as well, including 
directly. And extra layer of protection rarely hurts.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/discussions/3009#discussioncomment-8980454
You are receiving this because you are subscribed to this thread.

Message ID: 
<rpm-software-management/rpm/repo-discussions/3009/comments/8980...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to