58 ms·
>This probably should be made clearer, but: Reproducible builds are necessary for the security of any such system. It's outlined in earlier blog posts. >Conseq
by Foxboron 5y ago
>This probably should be made clearer, but: Reproducible builds are necessary for the security of any such system. It's outlined in earlier blog posts.
>Consequently, the inclusion of reproducible build verification is taken as a premise.
That is a bit funny. We have had issues making the PHP package reproducible on Arch Linux for years. And I believe upstream has rejected patches which embeds uname into built artifacts.
I'm a bit unsure about the premise considering upstream doesn't seem interested solving this?
- CiPHPerCoder 5y agoThis is about PHP code (i.e. written in the scripting language, PHP), not the PHP interpreter. Since it's a scripting language, your build artifacts will be one of: - .diff / .patch - .zip / .tar / .tar.gz - .phar (rarely) Of these, only the last (PHP Archives) is mildly persnickety for build reproducibility. But it's easily fixed: https://github.com/paragonie/sodium_compat/blob/08ab867bbb6ab3e2f295d57d7ac0e0024739105e/dist/Makefile#L36-L38 https://github.com/paragonie/sodium_compat/blob/08ab867bbb6a...