Oh man, you talk like these tarballs are coming out of the blue! These is the stuff you are supposed to use when you develop your prototypes. If you can't deal with them in the first place, your product will not work. You just need a website where people can download them, which, sure would cost too much, because, you know, websites can cost up to few bucks per month these days..
I'm sure you won't use these tarballs to create the production stuff you ship, but that stuff doesn't come out of the blue either. You must have a prototype first, which at a given time you freeze.
Garrett: The ongoing fight against GPL enforcement
Posted Feb 2, 2012 9:27 UTC (Thu) by zyga (subscriber, #81533)
[Link]
If you have 3rd party suppliers that provide almost everything for you then this is a real problem. If you think everything is rebuilt then you surely have an idealistic view of how production works. Often all you do is build your app on top of a toolkit ant 3/4 of the "open source" code there is just whatever was provided by the supplier.
Now suppose a tarball you got does not properly match the binary (which you don't really care about as long as it works, you also don't have the time expertise or time to rebuild and test all components). Now you have a license compliance issue that puts your product at risk.