devrtz :debian: · @devrtz
260 followers · 825 posts · Server fosstodon.org
F-Droid · @fdroidorg
20002 followers · 83 posts · Server floss.social

Read about , signing keys, and binary repos in the latest blog post which tells you about the advantages and caveats, as well as important lessons learned. And remember to back up your keys! Especially the keystore used to sign your apps 😉

f-droid.org/2023/09/03/reprodu

#reproduciblebuilds #FDroid

Last updated 1 year ago

F-Droid · @fdroidorg
20002 followers · 83 posts · Server floss.social

Another update to our monthly overview of F-Droid apps published with Reproducible Builds: August saw 25 new RB apps added and 2 existing apps switch to RB, making 191 RB apps in total.

gitlab.com/obfusk/fdroid-misc-

#FDroid #reproduciblebuilds

Last updated 1 year ago

Vagrant Cascadian · @vagrantc
279 followers · 560 posts · Server floss.social

@Foxboron

And for quite some time as well (definitely golang 1.19 at least... but I do not see test results for 1.15 through 1.18).

What they are saying, of course, is we have made significant effort! :)

That said, they are apparently getting bit-for-bit identical comparing builds from two significantly different operating systems, Linux/x86-64 and Windows/x86-64, which is pretty impressive!

go.dev/blog/rebuild

#Debian #reproduciblebuilds

Last updated 1 year ago

FarLine99 · @FarLine99
0 followers · 67 posts · Server fosstodon.org

@pootriarch it is . android version supports . it does not require you to trust server because everything is encrypted client side, though it is also open-source. does not know anything about your contacts, it is as encrypted as messages, calls, metadata, etc. only things they know are last time you login and account creation date. that's it. it has good reputation for more than 10 years.

#opensource #reproduciblebuilds #signal

Last updated 1 year ago

Wolf480pl · @wolf480pl
1101 followers · 36031 posts · Server mstdn.io
F-Droid · @fdroidorg
19526 followers · 78 posts · Server floss.social

today at with 57 updated and 6 added apps:

* Mint Task: Simple todo manager
* WallFlow: beautiful wallpapers from wallhaven
* BoB: pregnancy tracking
* Traintime PDA: personal data assistant for XDU undergraduate
* App List: Contacts Organised by Group
* Safe Space: a vault for files

"Contacts Import" has switched to so you might need to un- and re-install the app if you use it.

Enjoy your and with :awesome:

#AndroidAppRain #FDroid #reproduciblebuilds #free #libre #Android #apps

Last updated 1 year ago

Evan J Rowley · @ejrowley
11 followers · 187 posts · Server mastodon.green

Sounds like OWASP recommends reproducible builds for software supply chain security. It's noteworthy that the Linux distributions leading are largely community-driven and non-enterprise. I'd love to see Reproduce Builds gain more traction, but I need to prepare myself emotionally for when it becomes another marketing buzzword abused by Fortune-100 tech companies / Gartner.

OWASP Lead Flags Gaping Hole in Software Supply Chain Security
darkreading.com/application-se

#reproduciblebuilds

Last updated 1 year ago

IzzyOnDroid ✅ · @IzzyOnDroid
3731 followers · 2256 posts · Server floss.social

You've read about F-Droid's recently? Now, the repo makes use of that implementation. How, you ask?

Well: part of the process is to compare APKs and make sure they carry the signature of their authors. That's done by fdroidserver whenever the YAML file of an app has "AllowedAPKSigningKeys:" defined. APKs with not-matching signatures are rejected. That's used by my repo now to make sure updates are "legit" (and not placed to the repo by a malicious actor). (1/4)

#reproduciblebuilds #IzzySoftRepo

Last updated 1 year ago

F-Droid · @fdroidorg
19081 followers · 73 posts · Server floss.social

Our monthly overview of F-Droid apps published with Reproducible Builds has just been updated: July saw 20 new RB apps added, making 165 RB apps in total.

gitlab.com/obfusk/fdroid-misc-

#FDroid #reproduciblebuilds

Last updated 1 year ago

Vagrant Cascadian · @vagrantc
263 followers · 538 posts · Server floss.social

@janneke @reproducible_builds

Fixed in git, should land on the site in a bit...

The broken link was probably misplaced in transition from the Debian wiki to the site:

wiki.debian.org/ReproducibleBu

#reproduciblebuilds

Last updated 1 year ago

Vagrant Cascadian · @vagrantc
241 followers · 506 posts · Server floss.social

Gave a talk at yesterday about and and how close we are to actually counter the infamous attack.

The slides are packaged as a Debian package, including a signed .buildinfo file, so you should be able to recreate my slides bit-for-bit identically!

aikidev.net/~vagrant/talks/202

However, my actual talk included a fair amount of non-determinism, thanks for all the great questions!

2023.fossy.us/schedule/present

Videos should be available soon!

#fossy #reproduciblebuilds #bootstrappablebuilds #trustingtrust

Last updated 1 year ago

Ludovic Courtès · @civodul
1275 followers · 4615 posts · Server toot.aquilenet.fr

Interesting issue: npm package installation depends on whether source files have hard links, making it stateful (or “non-deterministic” depending on how you look at it).
lists.gnu.org/archive/html/gui

Cc: @reproducible_builds

#reproduciblebuilds

Last updated 1 year ago

Vagrant Cascadian · @vagrantc
241 followers · 506 posts · Server floss.social

@civodul @jas4711

And looking at the it resulted in testing for which might not have happened otherwise! :)

blog.josefsson.org/2023/04/10/

#silverlining #reproduciblebuilds #trisquel

Last updated 1 year ago

Lunar · @lunar
1514 followers · 9365 posts · Server mastodon.potager.org

“repro-env” by kpcyrd
github.com/kpcyrd/repro-env

> Imagine you had a tool that takes a config like this:
>
> # repro-env.toml
> [container]
> image = "rust:1-alpine3.18"
>
> and turns it into something like this:
>
> # repro-env.lock
> [container]
> image = "rust@sha256:22760a18d52be83a74f5df8b190b8e9baa1e6ce7d9bda40630acc8ba5328a2fd"

#reproduciblebuilds

Last updated 1 year ago

Andrius Ĺ tikonas · @stikonas
18 followers · 110 posts · Server fosstodon.org

Spent part of my at looking at bootstrapping 0.9.26 from on architecture. And thanks to mantainer @janneke for his help debugging various issues. We can now build initial binary and it can even run some simple commands such as --help or -vv.

Unfortunately, we still hit some critical bugs when trying to use this tcc binary to rebuild itself but hopefully we are not far now.



#rechageday #amd #TinyCC #GNUmes #x86_64 #mes #tcc #bootstrappable #bootstrappablebuilds #reproduciblebuilds

Last updated 1 year ago

Janneke · @janneke
634 followers · 180 posts · Server todon.nl

Talk at IEEE S&P 2023 "Oakland" by Marcel Fourné "It’s like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security"

youtube.com/watch?v=H0A2cSejlZ




@reproducible_builds

#reproduciblebuilds #bootstrappablebuilds #bootstrappable

Last updated 1 year ago

Ludovic Courtès · @civodul
1235 followers · 4510 posts · Server toot.aquilenet.fr

“It’s like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security”
saschafahl.de/static/paper/rep

#reproduciblebuilds

Last updated 1 year ago

Kimimaru · @Kimimaru
43 followers · 433 posts · Server mastodon.gamedev.place

Does anyone have experience making reproducible builds for .NET projects?

#reproduciblebuilds #dotnet #csharp #freesoftware

Last updated 1 year ago

DocRekd · @docRekd
17 followers · 507 posts · Server hachyderm.io

@orowith2os "Insane blog posts" are some of the most entertaining one.

Besides many people are interested into bootstrapping like the community and the larger , no matter how insane it can get

#rust #nixos #reproduciblebuilds

Last updated 1 year ago