Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

reproducible builds #9039

Open
mixxxbot opened this issue Aug 23, 2022 · 4 comments
Open

reproducible builds #9039

mixxxbot opened this issue Aug 23, 2022 · 4 comments
Labels

Comments

@mixxxbot
Copy link
Collaborator

Reported by: Be-ing
Date: 2017-12-31T16:55:27Z
Status: New
Importance: Wishlist
Launchpad Issue: lp1740695


We distribute binaries that are downloaded millions of times. We should be able to be certain that the binaries have not been compromised. We can only be sure if our builds are 100% reproducible: https://reproducible-builds.org/

@mixxxbot
Copy link
Collaborator Author

Commented by: sblaisot
Date: 2017-12-31T17:37:50Z


100% bit-to-bit reproductible build under windows using MSVS seems an impossible goal because the executable itself contain (at least) the build date.

@mixxxbot
Copy link
Collaborator Author

Commented by: Be-ing
Date: 2017-12-31T17:50:52Z


Someone made tool to fix that: https://github.com/jasonwhite/ducible

@mixxxbot
Copy link
Collaborator Author

Commented by: sblaisot
Date: 2018-01-01T14:37:51Z


Here are the things I can think of :

@mixxxbot
Copy link
Collaborator Author

Commented by: rryan
Date: 2018-05-27T17:30:03Z


I'm all for reproducible builds, but this is feasible for 2.2? It's quite a big project -- particularly b/c our dependencies need to be reproducible and we have a lot of dependencies.

@mixxxbot mixxxbot transferred this issue from another repository Aug 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant