@ariadne I'm interested in this for software trust purposes (#ReproBuilds level and trust of underlying codebases & maintainerships).
@aral There's a lot of tie-in that can be had with #ReproBuilds here. Allowing separate vetting of the claim that "package matches the source" from "I've reviewed the source changes and they seem to do what they're advertised as", etc.
@Foxboron Very possibly! There was an epic thread with taviso (the one where he blocked me and a bunch of other folks for not agreeing with him that they're useless) a long time ago on birdsite over the value of #reprobuilds and webs of trust, where a lot of this came up.
Particularly, the value Twitter had as a unified public social graph of curated trust-as-source-of-information relationships.
The same kind of trust-as-source-of-information has come up in #reprobuilds and software provenance fields.
@fsf @conservancy @fsfe #GNU Mes 0.24 released, closing the gap with Stage0: the Full Source Bootstrap is here!
The @GuixHPC package graph is now rooted in hex0, a 357-byte binary & ASCII-equivalent https://github.com/oriansj/bootstrap-seeds/blob/master/POSIX/x86/hex0_x86.hex0…
@fsf
@fsfe
@conservancy
@nixos
@NGIZero
@reproducible_builds
#reprobuilds #gnutools #NLnetFDN
#gnu #reprobuilds #gnutools #nlnetfdn
In an upcoming #IEEESoftware paper with Chris Lamb, we describe the #ReproducibleBuilds approach to increase the integrity of [#opensource] software #SupplyChains and how that worked out for #Debian.
#openaccess preprint: https://arxiv.org/abs/2104.06020
#IEEESoftware #reproduciblebuilds #opensource #supplychains #debian #openaccess #freesoftware #foss #reprobuilds
GNU Mes 0.23 released!
Mes now supports ARM! For development it also builds with @gnutools' gcc-10 and @guilelang 3.0
https://lists.gnu.org/archive/html/info-gnu/2021-03/msg00002.html
#nlnetfdn #bootstrappable #reprobuilds #gnutools
We closed the gap between Stage0 and #GNU Mes: the Full Source Bootstrap is near!
The package graph is now rooted in hex0, a #357-byte binary & ASCII-equivalent https://github.com/oriansj/bootstrap-seeds/blob/master/POSIX/x86/hex0_x86.hex0
Make your distro #bootstrappable!
@fsf
@conservancy
@fsfe
@nixos@gup.pe
#reprobuilds #gnutools #NLnetFDN
#gnu #bootstrappable #reprobuilds #gnutools #nlnetfdn