From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp10.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms5.migadu.com with LMTPS id mB1nAbhvk2PFVgEAbAwnHQ (envelope-from ) for ; Fri, 09 Dec 2022 18:26:16 +0100 Received: from aspmx1.migadu.com ([2001:41d0:8:6d80::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp10.migadu.com with LMTPS id EICDALhvk2MZdgEAG6o9tA (envelope-from ) for ; Fri, 09 Dec 2022 18:26:16 +0100 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id A1CE72CD55 for ; Fri, 9 Dec 2022 18:26:15 +0100 (CET) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1p3h85-0002fm-BL; Fri, 09 Dec 2022 12:25:45 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1p3h84-0002fY-4i for guix-devel@gnu.org; Fri, 09 Dec 2022 12:25:44 -0500 Received: from knopi.disroot.org ([178.21.23.139]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1p3h82-0004tu-Mx for guix-devel@gnu.org; Fri, 09 Dec 2022 12:25:43 -0500 Received: from localhost (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 0E17B40AF5; Fri, 9 Dec 2022 18:25:41 +0100 (CET) X-Virus-Scanned: SPAM Filter at disroot.org Received: from knopi.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KffoGpXbufWT; Fri, 9 Dec 2022 18:25:40 +0100 (CET) Content-Type: multipart/signed; boundary=5d37ed2d56851d9a606d58a0615c9fed81dafa9297b4cd1ef2f1eee92540; micalg=pgp-sha512; protocol="application/pgp-signature" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1670606740; bh=d6jEMI9yUNPOkJ3MNygZf5rWFrTMcWdQ69OXl0wF8/k=; h=Date:Cc:Subject:From:To:References:In-Reply-To; b=V0WgAJa6D5foL/CfTruEv3gLHeHgxGnpSQMs3zQQeDm6HX/FSCTd3omC1nvKirLRl PFowLHVye67QoyKFDDPcsln0y581r08gqLv5QIA43H2384m6ykgyD4rIUizfAFVnSW u3DpGdbiKlYiy3iuj1c7IWc8fe2MLMYc6L9i2gZNF93UOSHapWWpGAtypJOQtfDoKt u+RJQDpo5dMYplK3BYgdT8U631PbaDlRGVst53H6zNRcBOj9SPotqH/eiyL/a5HwWP QMsbELZzD0mXvLTkxwlt3e7kgnwbpDMkDUKkdDNKHNfDpLz4ZlTya5VyJH8v9G1GL4 UXTZPR7fDyPnQ== Date: Fri, 09 Dec 2022 17:25:35 +0000 Message-Id: Cc: =?utf-8?q?=E5=AE=8B=E6=96=87=E6=AD=A6?= , Subject: Re: Dissecting Guix -- blog post series From: "(" To: References: <87v8ml823k.fsf@envs.net> <20221209093250.GA5724@LionPure> In-Reply-To: <20221209093250.GA5724@LionPure> Received-SPF: pass client-ip=178.21.23.139; envelope-from=paren@disroot.org; helo=knopi.disroot.org X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, MIME_HEADER_CTYPE_ONLY=0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: guix-devel-bounces+larch=yhetil.org@gnu.org X-Migadu-Country: US X-Migadu-Flow: FLOW_IN ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1670606775; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:content-type:content-type: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post:dkim-signature; bh=J6b/u9nV27aYXtMXEd4ATMsq5W/UqlwZuC7ioafI4rU=; b=JJ4Q/LNjSsC+X8tvXPhTED91bWUikTjVlNk7BR6T2kGla58JB6DGJ75HdC3OPYlXOvAVrI ptFhKSACXn6c9TJQmy5Bt/CAasu5d3DUZyLWy4IQGP8VSqwxF9fE4XJCYOc+m6xwDJUkq2 7m2uPA2RWm7Qxgck2m6T38zblVw7pz5PpVHZNkX9cV2djSVNWIFq3ZezXec2eF1b+FCTjJ bQxah/3/GPRLDcyU8TIda8lokd+heo4cQv6iCXfLrWXRpJHG0BOFQNrLhQX9Yd4qTws9Mf 57cjp+ePbQ3M2HQHhEihKvSrZKtlqbGyV/q/6sAyiP7h7Dkka5hTcG8JixVsag== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=pass header.d=disroot.org header.s=mail header.b=V0WgAJa6; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=reject) header.from=disroot.org ARC-Seal: i=1; s=key1; d=yhetil.org; t=1670606775; a=rsa-sha256; cv=none; b=oAFSLhJJmFPVfo8bTHgh9NxvunPKoMr4mikDtZ7WeQDpK2y+DDO4/nM137E2BVJAq2xxz9 gthSZPo8KyayVDJH774mBSE5TvPS71dWgkoXYpmUYwhqXDlknPE1F7MS9qeCshg5LYaK/o 4eKqwmUUWGA676ZsUv5fvX/xj3KHesmcyZdbdfScFnqf4g5JyepGvUit6AkiNFZbxs1h4u S1SK33uIbFdjV/VuTBx5NzxBCcXbEadqVI7q5+Vzdp1hptwDGwS1QHqUhb4mlbyurJvXDZ 9mgXxeREWGlGneBvS+DXA1krsmN6CxEOTwAk7VnFxnAXtzPCet65vn3hbh8jzQ== X-Migadu-Spam-Score: -7.44 X-Spam-Score: -7.44 X-Migadu-Queue-Id: A1CE72CD55 X-Migadu-Scanner: scn0.migadu.com Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=disroot.org header.s=mail header.b=V0WgAJa6; spf=pass (aspmx1.migadu.com: domain of "guix-devel-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-devel-bounces+larch=yhetil.org@gnu.org"; dmarc=pass (policy=reject) header.from=disroot.org X-TUID: ZWAoWgLJWvVt --5d37ed2d56851d9a606d58a0615c9fed81dafa9297b4cd1ef2f1eee92540 Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Heya, On Fri Dec 9, 2022 at 9:32 AM GMT, wrote: > How does a gullible noob like me know what the dangers might be, (e.g. ht= tp:) > and how to avoid (most of) them by finding a guix version that has been > gone through with a fine-tooth comb by trusted guix devs and has been > re-hosted at gitlab or gnu.org, etc ... for added security? Sorry, I don't really understand; how is this relevant to derivations? :) -- ( --5d37ed2d56851d9a606d58a0615c9fed81dafa9297b4cd1ef2f1eee92540 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEE6Vh10NblKE5doNlW7ImHg/nqI20FAmOTb48ACgkQ7ImHg/nq I23GngwA39v13mYSyMIVQnV5cNSVKP4X5CBn9NmHHe/6wIdXIvVyp3BbxXNy3JUl nriDzdefLm4n3cfQesBW1tgRemp9IcZ0a2mAKmemt8zx+fdEFkQHM0XTMhIlpjpZ j8yDdp1LsSBUwCDGB0bCCJs/+unV50NgIrlLxKAMd/mX0B30ncuWn2WlsuJidcSs n87mK+TjH5zTQBw/Pb+sUdvTRCVFSSDkVfTYpmtWfcfZeMNaQnHshKJ5c01Lc0Xz qF5j8mZW+tZw3y9VyJQ6kwniv3HIgJO5NUggWMC0PnPKwOjXZPzDSucYFeX2SolJ 4tnyQzu2puzAlHNSv+CZghnb0bmBBTDgl4WN9CPxLqelI5WTWn6o9pMDUaCIb2sf bKX8jQBwmdXgokjwA/BrsquCxJqOy5s0AgCBZBfwvGWLSbbiuavWgvM3bHPsKVHu rN4d721KIrDrGinnljUGcACXAIqWAVDlCeg9qTuI3O180GZ2rjc9MaX2y9aCT3/T 5V5I1H/5 =6yHy -----END PGP SIGNATURE----- --5d37ed2d56851d9a606d58a0615c9fed81dafa9297b4cd1ef2f1eee92540--