Use of .buildinfo in buster

Chris Lamb lamby at debian.org
Mon Jul 24 22:01:14 UTC 2017


Adrian Bunk wrote:

> How is this supposed to work for DSAs?
> Do you want to claim a security update is reproducible without checking,
> or do you want to delay DSAs until the packages have been reproduced 
> for all architectures?
[…] 
> Why should this be a per-package user-visible issue instead of aiming
> at giving guarantess for all packages in main?
[…]
> There is also a certain amount of WTF

Completely agree with all the above. These are all the kind of issues and
parameters my proof-of-concept intended to raise :)


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb, Debian Project Leader
     `. `'`      lamby at debian.org / chris-lamb.co.uk
       `-



More information about the Reproducible-builds mailing list