logoalt Hacker News

dborehamtoday at 1:59 PM1 replyview on HN

I think the general idea that your supply chain should be rooted in source repositories and associated commit hashes is the right one. Tooling can be made to automate the process of putting together a product from those defined sources. Some languages/systems already have some support for this. E.g. Golang and Rust. The concept of a "binary" artifact is really dead now everyone uses git and builds are quick. It lives on in things like npm and docker hub but we don't actually need it.


Replies

Zardoz84today at 4:25 PM

DUB , for D Lang does that.