home.social

#reproducablebuilds — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #reproducablebuilds, aggregated by home.social.

  1. @dolmen Many systems are based on #bootstrapping and #reproducableBuilds
    bootstrappable.org/
    reproducible-builds.org/
    en.wikipedia.org/wiki/Bootstra

    These ensure that the build system integrity cannot be tampered with. One example of such system is openbuildservice.org/

    Here's a great read on the topic from #SUSE : documentation.suse.com/sbp/ser

    Generally Supply-chain Levels for Software Artifacts (#SLSA) framework is a great resource on this topic: slsa.dev/ #cybersecurity #infosec

  2. So I admit a certain degree of #FOMO with #NixOS. I tried installing it via their #Plasma #ISO #distro and it crashed on the install. What's the best way to install Nix for a newb? I want to be able to build this glorious config file for #ReproducableBuilds but where do I start with that? Any help is appreciated.

  3. At the moment Holger Levsen #Debian #reproducableBuilds talks about "Reproducible Builds, the first ten years" at the @fsfe 's track at #fossnorth

  4. @0
    Is #Signal's apk build even reproducable?

    Last we heard they proclaim to be #openSource but their build isn't reproducable and thus you don't **really** know the code you are running on your device when you are running it.

    Doesn't it also use non-free network services?

    #reproducableBuilds #floss #freeLicense

    @Ayior @jcbrand