You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
While tzdata and ca-certificates release mostly data instead of source code, they are arguably critical to trust. I suggest adding (and tracking) the "build" dependencies of both.
Sure. And while there might be others, the named entities ca-certificates and tzdata are among the most popular packages providing said broader concepts.
While
tzdata
andca-certificates
release mostly data instead of source code, they are arguably critical to trust. I suggest adding (and tracking) the "build" dependencies of both.For example, in Debian-based systems,
tzdata
not only relies onmake
(as all Debian packages do) but also ongawk
orzic
fromlibc
, e.g., https://sources.debian.org/src/tzdata/2021e-1/debian/rules/#L28Similarly,
ca-certificates
depends onpython3
and thecryptography
module, as well as OpenSSL: https://sources.debian.org/src/ca-certificates/20211016/debian/control/#L6The text was updated successfully, but these errors were encountered: