You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We need to define a format to communicate meaningful rebuild failures. This will provide an explicit signal to downstream consumers that we are failing to rebuild a package.
This will required some nuanced framing because not every RebuildFailure will indicate malicious code in the upstream. Some RebuildFailures will be due to a change in the build toolchain, or other benign development processes. However, this RebuildFailure attestation type will be our signal for alerting the community when a package contains malicious source that was not present in the upstream.
The text was updated successfully, but these errors were encountered:
We need to define a format to communicate meaningful rebuild failures. This will provide an explicit signal to downstream consumers that we are failing to rebuild a package.
This will required some nuanced framing because not every RebuildFailure will indicate malicious code in the upstream. Some RebuildFailures will be due to a change in the build toolchain, or other benign development processes. However, this RebuildFailure attestation type will be our signal for alerting the community when a package contains malicious source that was not present in the upstream.
The text was updated successfully, but these errors were encountered: