On Mon, Apr 22, 2019 at 02:17:53PM -0400, David A. Wheeler wrote: > > It might be non-obvious from where those copies are coming from, or IOW > > that the hashes of these sources are part of the build instructions. > I don't think that should be specified in the definition. > It shouldn't matter how you got copies, as long as you have them. > Having hashes of sources in the build instructions can be a useful > implementation > approach, but I don't think those should be required either (if you have the > actual > sources, there's no particular reason to require the hashes as well).
agreed to all of that. but then I wouldnt mention 'copies'... (because
else it implies all those questions mentioned above.)
> Fair point. I think removing that word "both" is good enough.
yup
> New version of the summary motivation is:
>
> Reproducible builds help counter unintentional errors and malicious builds.
I think I'd like to see a full patch... else it's much harder to
review..
> Fair point, and it's probably unnecessary to mention either "set" or "sets".
> Also, I don't think the project is developing all the tools that could be
> useful.
*nods*
> How about this as a summary description of the project?:
>
> The reproducible builds project is developing tools and recommended
> software development practices to enable all builds to be reproducible.
>
> Again, the goal is to maximize clarity for newcomers.
again, I think I'd like to see a full patch... :)
& thanks as well!
--
tschau,
Holger
-------------------------------------------------------------------------------
holger@(debian|reproducible-builds|layer-acht).org
PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C
signature.asc
Description: PGP signature
_______________________________________________ [email protected] mailing list To change your subscription options, visit https://lists.reproducible-builds.org/listinfo/rb-general. To unsubscribe, send an email to [email protected].
