Skip to content

Reproducible builds and strict dependency verification #30685

Closed
@pboguslawski

Description

@pboguslawski

Description

Gitea build process was found not reproducible. Please force strict verification against committed checksums for every dependency to avoid surprises and to better protect against supply chain attacks.

npi ci should probably be used instead npm install and break install process if any checksum mismatch occurs. Same for go modules (if works different now).

Related: #29326 (comment)

Gitea Version

1.21

Can you reproduce the bug on the Gitea demo site?

No

Log Gist

No response

Screenshots

No response

Git Version

No response

Operating System

No response

How are you running Gitea?

Compiled from sources.

Database

MySQL/MariaDB

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions