[Reproducible-builds] Announcing Whonix's First Implementation of Verifiable Builds

Paul Wise pabs at debian.org
Wed Dec 11 15:44:31 UTC 2013


On Wed, Dec 11, 2013 at 10:55 PM, adrelanos wrote:

> you may or may not be interested, that Whonix [1] (a derivative of
> Debian) first implementation of verifiable builds has been finished.

Interesting stuff, thanks for mentioning it here.

> How it works (very brief)...

A reasonable approach considering the lack of OEM-mode like
capabilities in Debian.

> And I also have a question. During Whonix's build process, after
> installing all packages inside the image, commands like
...
> are run. Is there perhaps a better way of temporarily getting rid of
> non-deterministic files than manually running these scripts, for
> example letting dpkg call those scripts?

A few links related to that:

http://lists.debian.org/debian-devel/2013/12/msg00046.html
http://lists.debian.org/debian-devel/2011/07/msg00694.html
https://wiki.debian.org/ReproducibleInstalls

-- 
bye,
pabs

http://wiki.debian.org/PaulWise



More information about the Reproducible-builds mailing list