Repository navigation
1.0.2
PassPony (Android) 1.0.2
Reproducible build fixes for F-Droid verification. No user-facing
changes; the app is functionally identical to 1.0.0.
- The Rust core's embedded OpenSSL build info is now host-independent:
the build timestamp is pinned to a fixed epoch on every builder, and
the compiler path is normalized through a fixed location instead of
recording wherever the NDK happens to be installed - Together these make a from-source rebuild on any Linux host,
F-Droid's build servers included, byte-identical to the published
release
Verification
- Content hash:
831e139a4db3a1cd2aaa1eeb14ce083fbe71a974d5a7c44c8db3f959207f3aa2 - SHA-256 checksums: see
PassPonyAndroid-1.0.2-SHA256SUMS.txt - Reproduce this build yourself:
tools/verify_repro.sh rebuild v1.0.2 PassPonyAndroid-1.0.2-foss.apk
See docs/REPRODUCIBLE.md for what "content hash" means and why it isn't a whole-file SHA-256.