> Valve is generously providing backing for two
critical projects that will have a huge impact on our distribution: a
build service infrastructure and a secure signing enclave.
It sounds like Valve is investing in the security of Arch Linux's build infrastructure to prevent supply chain attacks.
cyanmagenta
I really hope Arch moves to a model like Debian where all packages are built by a central build server. The current strategy—having dozens of different developers compile stuff on their laptops, sign it personally, and then upload the binary blob—leaves a bit to be desired for obvious reasons.
Sabinus
It's incredible how, as a privately owned company, Valve avoids the profit chasing short termism of the publically traded companies.
It sounds like Valve is investing in the security of Arch Linux's build infrastructure to prevent supply chain attacks.