Security celebrities have been shitting on the PGP Web Of Trust as an idea we should abandon in favor of centralizing trust on corpos.

Meanwhile the internet is filling with AI bots using fake corpo accounts and no one can tell who is human anymore. Huh.

WoT has never mattered more, and it is time we anchor modern tooling back to the human roots that built the internet.

My fellow [Stageˣ] maintainer Kron, Zoë Finja Emilia makes a strong visual case.

https://kron.fi/en/posts/stagex-web-of-trust/

How do you trust a new Linux Distribution?

Who do you trust (… and how do you trust the new Linux Distribution StageX?) Do you trust your best friend from childhood? Do you trust your chosen Distribution for your Homelab? For your Workplace? Psychology says there are roughly two types of trust. Direct and Transitive trust. Direct trust is you trusting your best friend. Transitive trust is your best friend assuring you another person is also trustworthy and you listening to their word because you trust them.

Zoë's Blog

Read more about our work on [Stageˣ] here: https://stagex.tools

All the pain of supply chain attacks is self inflicted. We actually can fix this.

Home | [Stageˣ]

A container-native, full-source bootstrapped, and reproducible toolchain to build all the things.

@lrvick is there a way to request packages? There is a Postgres one, but not a timescaledb package available.

@nabeards Packages are just containerfiles so it is not hard to write them yourself in most cases: https://codeberg.org/stagex/stagex/src/branch/main/packages/core/curl/Containerfile

But file issues for things you want to see, or PRs if you get something building locally.

Need any help, drop into #stagex:matrix.org

stagex/packages/core/curl/Containerfile at main

stagex - A container-native, full-source bootstrapped, and reproducible toolchain to build all the things

Codeberg.org