But if there weren't a workflow to do this it wouldn't mean repro builds are useless. It would be a flaw in the store's app delivery model that needs fixing.
-
-
love to oblige trying to argue with someone who willfully ignores what I say. Have a great day!
-
I'm not ignoring what you're saying. You're adding arbitrary restrictions, I asked "Can't you just use the binary you built?", No, apparently "It's not 1999, I can't build it, I need someone else to", "Why can't you use their binary?" "I don't trust them"...?!
- 28 more replies
New conversation -
-
-
But open source in absence of reproducible builds isn’t really a solution, unless you’re going to independently audit the entire source every time. A reproducible build lets you at least verify that you can build the same thing as the official builds from the same source/tools.
-
Essentially, it allows third parties to verify that e.g. the official builds have not been tampered with wrt the publicly available source code. The model isn’t unlike the PGP Web Of Trust, for better or for worse.
- 19 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.