Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

does anyone practice dual build pipeline? eg: 1 by your devops team and another one by your security team and compare binaries hash later. To verify everything is reproducible.

is it a common practice?



It is not common outside of security inclined communities like cryptocurrencies. It should be and we are slowly moving there.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: