On May 21, Lucas De Marchi <lucas.de.mar...@gmail.com> wrote: > And how is this signature prepared? Since it needs the compiled > module it would be a matter of changing the compiler, even minor > version, to invalidate the argument of reproducible build. It seems > very fragile to me. But this is the whole point of reproducible builds: knowing that if you start from the same sources and build enviroment, and distributions do, then you will get the same results. Building gcc is reproducibile as well... Reproducibility with a different compiler has never been a goal.
-- ciao, Marco
signature.asc
Description: PGP signature