I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

  • refalo@programming.dev
    link
    fedilink
    arrow-up
    1
    ·
    2 天前

    The problem is not near enough projects support reproducible builds, and many that do aren’t being regularly verified, at least publicly.

    • Ferk@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 天前

      Yes, that’s why im saying that this kind of problem isn’t something particular about this project.

      In fact I’m not sure if it’s the case that the builds aren’t reproducible/verifiable for these binaries in ventoy. And if they aren’t, then I think it’s in the upstream projects where it should be fixed.

      Of course ventoy should try to provide traceability for the specific versions they are using, but in principle I don’t think it should be a problem to rely on those binaries if they are verifiable… just the same way as we rely on binaries for many dynamic libraries in a lot of distributions. After all, Ventoy is closer to being an OS/distribution than a particular program.