contrib: improvements from Marek's comments

This commit is contained in:
Frédéric Pierret (fepitre) 2019-11-11 17:35:34 +01:00
parent a550680600
commit 96069def46
No known key found for this signature in database
GPG Key ID: 484010B5CDC576E2

View File

@ -74,9 +74,11 @@ The review procedure is as follows:
In all the cases, the first condition to be validated by the QCR's review is to ensure that the contribution **will not** hijack any core packages of [QubesOS] and of course, none of the [QubesOS-contrib] packages too. More precisely, particular attention to the whole build pipeline will be made with a specific review of:
- Package dependencies,
- Build scripts,
- Build scripts (including downloaded ones),
- All downloaded components should be verified against static hash,
- RPM/DEB installation scripts (e.g. looking at constraints who would hijack other packages),
- Makefiles,
- Package build [reproducible]
and any steps which would result in partial/total compromise of legitimate components.
@ -104,4 +106,4 @@ If you do not act on your maintainer duties for a given package for an extended
[QubesOS]: https://github.com/QubesOS
[QubesOS-contrib]: https://github.com/QubesOS-contrib
[qubes-issues]: https://github.com/QubesOS/qubes-issues/issues/
[reproducible]: https://reproducible-builds.org/