Skip to main content

Search

Items tagged with: reproduciblebuilds


https://linderud.dev/blog/nixos-is-not-reproducible/

#Nix #nixos #ReproducibleBuilds


So, Philipp Kern dropped by asking if we could do some #ReproducibleBuilds verifications of recent Debian Security updates, given, well the whole #xz mess... and that our build infrastructure may have run compromised code at some point...

So I did a quick pass at a handful of updates and everything verified ok so far, though I skipped some of the probably more juicy targets such as chromium and firefox:

https://lists.reproducible-builds.org/pipermail/rb-general/2024-March/003321.html

Debian is reproducible enough to at least try this sort of thing!


I independently reproduced the #NixOS minimal installation ISO!

This is an amazing milestone for me personally: I've been involved in #ReproducibleBuilds since 2017 and #NixOS since 2019, and have been slowly chipping away at this problem. While there is much more to do to further reap the benefits of reproducibility, this is a long-awaited tangible benefit.

For more about the What, Why, How and What Next, check the post below :)

https://discourse.nixos.org/t/nixos-reproducible-builds-minimal-installation-iso-successfully-independently-rebuilt/34756


We've updated our monthly overview of F-Droid apps published with Reproducible Builds again: 21 new RB apps were added in June, making 145 RB apps in total.

https://gitlab.com/obfusk/fdroid-misc-scripts/-/blob/master/reproducible/overview.md

#FDroid #ReproducibleBuilds


We recently updated the @fdroidorg Inclusion How-To with a new section explaining why we consider #ReproducibleBuilds to be best practice and are hoping developers will support our efforts to make as many (new) apps reproducible as we reasonably can (whilst hopefully making sure it's clear this is not a mandatory requirement):

https://f-droid.org/docs/Inclusion_How-To/#reproducible-builds


Not too long ago, your two hands would have been enough to count the #reproducibleBuilds at @fdroidorg – but now it doesn't even help taking your shoes off to call your toes in. It's 50 now, and counting! I just successfully got an author's and my own first RB in ("with a little help from my friends"), and have 2 more pending :awesome:

So yes: expect more and more apps this way now. Install from #FDroid – update from Github if needed; signature matches. Just the GUI needs to show that now…


Have you heard about #ReproducibleBuilds? This is one of the biggest #security benefits of #FOSS. On #Android, this technique ensures that the #FDroid version of an app exactly matches the developer's version.

Read our article below for more details and to see how easy it is for developers to get set up:
https://f-droid.org/en/2023/01/15/towards-a-reproducible-fdroid.html

⇧