I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

  • refalo@programming.dev
    link
    fedilink
    arrow-up
    3
    ·
    2 months ago

    The problem is not near enough projects support reproducible builds, and many that do aren’t being regularly verified, at least publicly.

    • Ferk
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 months ago

      Yes, that’s why im saying that this kind of problem isn’t something particular about this project.

      In fact I’m not sure if it’s the case that the builds aren’t reproducible/verifiable for these binaries in ventoy. And if they aren’t, then I think it’s in the upstream projects where it should be fixed.

      Of course ventoy should try to provide traceability for the specific versions they are using, but in principle I don’t think it should be a problem to rely on those binaries if they are verifiable… just the same way as we rely on binaries for many dynamic libraries in a lot of distributions. After all, Ventoy is closer to being an OS/distribution than a particular program.