rene_mobile’s avatarrene_mobile’s Twitter Archive—№ 5,419

  1. While I haven't actually contributed anything to this release myself, I am proud of and thankful to my fellow Debian Developers for making this happen. Now it's time to update :) Hopefully I'll manage to contribute again to the next release. @debian/1147683799393636355
    1. …in reply to @rene_mobile
      "Thanks to the Reproducible Builds project, over 91% of the source packages included in Debian 10 will build bit-for-bit identical binary packages."
      1. …in reply to @rene_mobile
        "This is an important verification feature which protects users against malicious attempts to tamper with compilers and build networks. Future Debian releases will include tools and metadata so that end-users can validate the provenance of packages within the archive."
        1. …in reply to @rene_mobile
          @debian has been pioneering advances in reproducible builds for many years, and other projects benefit immensely. On the Android side, we are also aiming for fully reproducible AOSP builds as yet another defense against insider attacks. It's not trivial to get there, though ;-)