Re: Reproducible Builds for recent Debian security updates

2024-03-31 Thread Salvatore Bonaccorso
Hi, On Sat, Mar 30, 2024 at 03:30:57PM -0700, Vagrant Cascadian wrote: > On 2024-03-30, Vagrant Cascadian wrote: > > On 2024-03-30, Salvatore Bonaccorso wrote: > >> On Fri, Mar 29, 2024 at 07:38:35PM -0700, Vagrant Cascadian wrote: > >>> Philipp Kern asked about trying to do reproducible builds

Re: Reproducible Builds for recent Debian security updates

2024-03-30 Thread Vagrant Cascadian
On 2024-03-29, Vagrant Cascadian wrote: > So far, I have not found any reproducibility issues; everything I tested > I was able to get to build bit-for-bit identical with what is in the > Debian archive. > > I only tested bookworm security updates (not bullseye) ... > Not yet finished building: >

Re: Reproducible Builds for recent Debian security updates

2024-03-30 Thread Vagrant Cascadian
On 2024-03-30, Vagrant Cascadian wrote: > On 2024-03-30, Salvatore Bonaccorso wrote: >> On Fri, Mar 29, 2024 at 07:38:35PM -0700, Vagrant Cascadian wrote: >>> Philipp Kern asked about trying to do reproducible builds checks for >>> recent security updates to try to gain confidence about Debian's

Re: Reproducible Builds for recent Debian security updates

2024-03-30 Thread Salvatore Bonaccorso
Hi, On Sat, Mar 30, 2024 at 03:05:03PM -0700, Vagrant Cascadian wrote: > On 2024-03-30, Salvatore Bonaccorso wrote: > > On Fri, Mar 29, 2024 at 07:38:35PM -0700, Vagrant Cascadian wrote: > >> Philipp Kern asked about trying to do reproducible builds checks for > >> recent security updates to try

Re: Reproducible Builds for recent Debian security updates

2024-03-30 Thread Vagrant Cascadian
On 2024-03-30, Salvatore Bonaccorso wrote: > On Fri, Mar 29, 2024 at 07:38:35PM -0700, Vagrant Cascadian wrote: >> Philipp Kern asked about trying to do reproducible builds checks for >> recent security updates to try to gain confidence about Debian's buildd >> infrastructure, given that they run

Re: Reproducible Builds for recent Debian security updates

2024-03-30 Thread Salvatore Bonaccorso
Hi Vagrant, On Fri, Mar 29, 2024 at 07:38:35PM -0700, Vagrant Cascadian wrote: > Philipp Kern asked about trying to do reproducible builds checks for > recent security updates to try to gain confidence about Debian's buildd > infrastructure, given that they run builds in sid chroots which may

Reproducible Builds for recent Debian security updates

2024-03-29 Thread Vagrant Cascadian
Philipp Kern asked about trying to do reproducible builds checks for recent security updates to try to gain confidence about Debian's buildd infrastructure, given that they run builds in sid chroots which may have used or built or run a vulnerable xz-utils... So far, I have not found any