Replies: 3 comments 4 replies
-
@xmfcx I'd like to discuss this in the next AWSG meeting (2023-07-11) |
Beta Was this translation helpful? Give feedback.
-
For reference, here's the relevant section in the Debian policy manual regarding packages that access the internet during the build step: https://www.debian.org/doc/debian-policy/ch-source.html#main-building-script-debian-rules This ensures that package builds are reproducible and avoid potential security risks. |
Beta Was this translation helpful? Give feedback.
-
At least there seems to be no objection from TIER IV about removing the download script from CMake. I do have one concern about how we want to set the default path in our example launch files. |
Beta Was this translation helpful? Give feedback.
-
There are some packages (mainly in perception), that download artifacts during the build process via
CMake
. This not only breaks the Debian generation tasks, but forces users who build Autoware to have access to the internet during the process, which is at best incovenient and at worst a security risk.I thought of several options to avoid this that I'd like to discuss in the next ASWG meeting:
I had already started working on option 3 (autowarefoundation/autoware.universe#3137), but moreover we need a policy so that new packages do not download artifacts from the internet.
Beta Was this translation helpful? Give feedback.
All reactions