-
-
Notifications
You must be signed in to change notification settings - Fork 141
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Add support for reproducible builds #778
Conversation
Please open a issue discussing what this is and follow the PR template. |
You havent discussed with any maintainers. |
I am a maintainer of RxUI, have been for years, thanks! |
There's no bullet point in your list that indicates we have to take an additional dependency and risk on this package. Just that we have to use source link which we already do. If it's a matter of code deterministic then we'd prefer just to take those settings directly |
You haven't been involved in the splat project for over 3 years. Nor any rxui project other than refit. No discussion just come bulling in with a PR then using dnf policy as a excuse that doesn't even have a hard requirement on this package |
The dependency is from the Foundation itself as the easiest "one click" way of getting things working. It can also be done in other ways too. There's no risk on that package, it's not third party, it's first party. I never stopped being a maintainer, just stepped back to focus on other things. This is a small build-time enhancement that improves the security of the package; there's not much discussion required for this. |
@clairernovotny a few things regarding this...
|
This reverts commit cd2cbb8.
Let's not #yolo merge things without discussion, even if they seem like good ideas. Splat is used by too many people to do stuff like that. |
I will point out that the discussion on this PR feels like a Code of Conduct violation. We have a template for Issues and Pull Requests that link to "How to Contribute". We ask that issues be opened, and a discussion started to foster a healthy community inside the ReactiveUI project. When presented with that constructive feedback, the response was less than professional. There is no acceptance of the responsibility for the actions demonstrated. No care was given to what is best for other project maintainers, let alone the overall community. No apology to those affected by our mistakes. |
Wow great conversation! Let's lock it to contributors just for a laugh and not because someone on Twitter just unhelpfully sent 27.3k Looky-Loos over to drop their $0.02 on my repo |
(to be 100% clear, if you're a collaborator and want to write more, please do!) |
Adds support for reproducible builds as required by the .NET Foundation project requirements: https://github.com/dotnet-foundation/projects#eligibility-criteria under the Code subsection.