• casual_turtle_stew_enjoyer@sh.itjust.works
    link
    fedilink
    arrow-up
    6
    arrow-down
    4
    ·
    7 months ago

    Nix is already beyond fucked because they actively dismiss the need for appropriate security measures to prevent supply chain attacks. There were multiple discussions about this over the years that appear to have succumbed to neglect.

    I wouldn’t trust nix, just like I don’t trust pip, brew, or a whole plethora of other package managers and repositories. They are just too neglectful