Do I really need nixpkgs cooldowns (determinate systems) for desktop use case?

That’s incorrect, only committers (in nixpkgs vocabulary) can merge their own PRs, and becoming a committer has its own review process that requires a fair amount of participation and trust in the community. Hence, the blog post is intentionally lying with terminology to cause fear, uncertainty, and doubt.

Can that committer trust be abused? Of course, same as any other open source project where someone built up years of goodwill only to throw it away, but a cooldown won’t solve that. If self-merges were banned, a malicious committer could easily create a sockpuppet account to submit PRs from, and build up goodwill with that account too.

A week-long delay wouldn’t help with accidental compromise either; I only know of one such compromise here, and the leaked token wasn’t noticed for ~3 years. I think we need a more thoughtful process to prevent such leakage.

It’s FUD to get people more dependent on their products.
It has about as much security (non-)benefit as Manjaro does with their cooldown :wink:

More specifically, it somehow requires someone to notice issues within a week and stop pulling from nixpkgs from that point onwards… I don’t see any evidence that they have the manpower for anything like that. More importantly, you will get delayed security updates, which is a bigger risk in my view especially given how many apps are browser-based.

16 Likes