Re: [RFC] php-community: a faster-moving, community-driven PHP.
| From: | Daniil Gentili | Date: | Sun, 15 Mar 2026 14:55:30 +0000 |
| Subject: | Re: [RFC] php-community: a faster-moving, community-driven PHP. | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-130344@lists.php.net to get a copy of this message | ||
>
>
> I worked on an automated release workflow[^1] for php-src a few years
> ago, but after discussions with others from various major project
> communities (including Apache, Linux, etc.), I realized the solution
> wasn't workable for one main reason:
>
> An automated workflow cannot sign builds and still be considered secure.
>
> Builds must be signed by a human on the machine where the build took
> place. Automating the signatures in the cloud significantly reduces
> trust and greatly increases the likelihood of a bad actor gaining access
> to sneak things into the build (e.g., through compromised GitHub
> Actions, etc.).
>
I strongly disagree.
I have way more trust in an automatic build environment with reproducible
(key word here) builds than in a (potentially corruptible) human that
pinkie swears no changes were made to an autogenerated configure contained
in released tarballs.
>