I think it is OK to call this "reproducible", it's a natural language word and these are always dependent on some context. Technically, everything is reproducible if you know the state of the machine when the original build was started. Some other projects give you a VM and tell you to build in the VM. That would be a "well-known process". But nobody really knows what's in the VM so it's not helpful for security. Having a strict definition of reproducibility, helps us be more convinced that the build process is really only dependent on the source code and build tools, and a very restricted set of other inputs.


