logoalt Hacker News

lrvicktoday at 8:16 AM5 repliesview on HN

The only binaries of uv in the world you can get that were full source bootstrapped from signed package commits to signed reviews to multi-signed deterministic artifacts are the ones from my teammates and I at stagex.

All keys on geodistributed smartcards held by maintainers tied to a web of trust going back 25 years with over 5000 keys.

https://stagex.tools/packages/core/uv/

Though thankful for clients that let individual maintainers work on stagex part time once in a while, we have had one donation ever for $50 as a project. (thanks)

Why is it a bunch of mostly unpaid volunteer hackers are putting more effort into supply chain security than OpenAI.

I am annoyed.


Replies

duskdozertoday at 9:15 AM

>Why is it a bunch of mostly unpaid volunteer hackers are putting more effort into supply chain security than OpenAI.

Unpaid volunteer hackers provide their work for free under licenses designed for the purpose of allowing companies like OpenAI to use their work without paying or contributing in any form. OpenAI wants to make the most money. Why would they spend any time or money on something they can get for free?

show 2 replies
saghmtoday at 10:27 AM

> Why is it a bunch of mostly unpaid volunteer hackers are putting more effort into supply chain security than OpenAI.

Didn't the acquisition only happen a few weeks ago? Wouldn't it be more alarming if OpenAI had gone in and forced them to change their build process? Unless you're claiming that the article is lying about this being a description of what they've already been doing for a while (which seems a bit outlandish without more evidence), it's not clear to me why you're attributing this process to the parent company.

Don't get me wrong; there's plenty you can criticize OpenAI over, and I'm not taking a stance on your technical claims, but it seems somewhat disingenuous to phrase it like this.

blitzartoday at 10:38 AM

The private jet wont fuel itself now will it.

pabs3today at 9:47 AM

What are you using for signed reviews?

show 1 reply
charcircuittoday at 12:17 PM

>Why is it a bunch of mostly unpaid volunteer hackers are putting more effort into supply chain security than OpenAI.

To be frank. Because more effort doesn't actually mean that something is more secure. Just because you check extra things or take extra steps that doesn't mean it actually results in tangibly better security.

show 1 reply