mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#reproduciblebuilds

1 Beitrag1 Beteiligte*r0 Beiträge heute
IzzyOnDroid ✅<p><span class="h-card" translate="no"><a href="https://chaos.social/@SylvieLorxu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>SylvieLorxu</span></a></span> And you can be affirmed it's the very same FOSS build, as at IzzyOnDroid it is a Reproducible Build – meaning, our builders built the APK from Sylvia's code, and ended up with a byte-by-byte identical APK.</p><p>Bonus points: updates usually reach you within 24h of Sylvia making them available. Our build cycles are pretty short: just a few hours, instead of a few days 😉 </p><p><a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a> <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/updates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>updates</span></a></p>
Vagrant Cascadian<p><a href="https://floss.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a> talk at <a href="https://floss.social/tags/FOSSY2025" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FOSSY2025</span></a> went pretty well today, presented by myself and my colleague Chris Lamb...</p><p>For bonus fun, I used the <a href="https://floss.social/tags/MNTReform" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MNTReform</span></a> to present!</p><p>Slides available:</p><p><a href="https://people.debian.org/~vagrant/fossy-2025/Nevermind-the-Checkboxes-heres-Reproducible-Builds.pdf" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">people.debian.org/~vagrant/fos</span><span class="invisible">sy-2025/Nevermind-the-Checkboxes-heres-Reproducible-Builds.pdf</span></a></p><p>... as well as a .buildinfo file if you want to try and bit-for-bit reproduce the slides, although I did it using an arm64 machine:</p><p><a href="https://people.debian.org/~vagrant/fossy-2025/nevermind-the-checkboxes_2025.08.02+fossy_all.buildinfo.asc" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">people.debian.org/~vagrant/fos</span><span class="invisible">sy-2025/nevermind-the-checkboxes_2025.08.02+fossy_all.buildinfo.asc</span></a></p><p>Video should be available in a month or so, hopefully?</p>
IzzyOnDroid ✅<p>W00t, w00t! New NeoStore (one of our F-Droid clients) arrived, now showing the RB status directly next to the versions of each app 🥳 </p><p><a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a> <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a></p>
Vagrant Cascadian<p><span class="h-card" translate="no"><a href="https://floss.social/@IzzyOnDroid" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>IzzyOnDroid</span></a></span> <span class="h-card" translate="no"><a href="https://floss.social/@bg443" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bg443</span></a></span> </p><p>I believe it will be recorded and live streamed ... presuming, of course, no serious intervention by gremlins!</p><p>I have not followed closely, but always glad to see all the work done verifying android apps!</p><p><a href="https://floss.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a> has definitely grown to span many different types of software, and really it should be helpful everywhere!</p>
🌈☔🌦️🍄🌱🍉<p>Reproducible here means you can compile a package/piece of software from source and end up with the exact same binary package on different machines and later in time. This isn't a feature one can just asume fron software but a serious security benefit as you can compare packages compiled on different systems and lowering the odds of compiler or toolchain code injections or exploits.</p><p><a href="https://chaos.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://chaos.social/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproduciblebuilds</span></a></p>
IzzyOnDroid ✅<p><span class="h-card" translate="no"><a href="https://floss.social/@vagrantc" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>vagrantc</span></a></span> will the session be recorded, for those who cannot attend in person? Running multiple RB verification builders for Android apps ourselves (see e.g. <a href="https://android.izzysoft.de/articles/named/iod-rbs-mirrors-clients" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">android.izzysoft.de/articles/n</span><span class="invisible">amed/iod-rbs-mirrors-clients</span></a> and <a href="https://codeberg.org/IzzyOnDroid/rbtlog" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">codeberg.org/IzzyOnDroid/rbtlog</span><span class="invisible"></span></a> plus <a href="https://codeberg.org/bg443/rbtlog" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">codeberg.org/bg443/rbtlog</span><span class="invisible"></span></a> / <a href="https://shields.rbtlog.dev/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">shields.rbtlog.dev/</span><span class="invisible"></span></a>), we're of course interested in what you and Chris have to say 🤗</p><p><span class="h-card" translate="no"><a href="https://floss.social/@bg443" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bg443</span></a></span> </p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a></p>
🌈☔🌦️🍄🌱🍉<p>92.04% of all packages in debian trixie are reproducible, 96.40% of the amd64 packages and 96.30% for arm64. ppc64el scores worst with 89.50%.</p><p><a href="https://reproduce.debian.net/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">reproduce.debian.net/</span><span class="invisible"></span></a></p><p><a href="https://chaos.social/tags/debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>debian</span></a> <a href="https://chaos.social/tags/trixie" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>trixie</span></a> <a href="https://chaos.social/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproduciblebuilds</span></a></p>
IzzyOnDroid ✅<p>😱 the Real Beast arrived!</p><p>666 apps (50.6%)</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
Vagrant Cascadian<p><span class="h-card" translate="no"><a href="https://social.vmbrasseur.com/@vmbrasseur" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>vmbrasseur</span></a></span> </p><p>So there!</p><p>Will be holding down a <a href="https://floss.social/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a> table and giving a related talk or two!</p><p>Looking forward to seeing folks!</p>
Risotto Bias<p><a href="https://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.googleblog.com/2025/0</span><span class="invisible">7/introducing-oss-rebuild-open-source.html</span></a> <a href="https://toot.risottobias.org/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://toot.risottobias.org/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproduciblebuilds</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, FlorisBoard 🥳</p><p><a href="https://apt.izzysoft.de/packages/dev.patrickgold.florisboard.beta" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/dev.p</span><span class="invisible">atrickgold.florisboard.beta</span></a></p><p>FlorisBoard is your versatile keyboard app, loaded with many features, keyboard layouts, skins and more. At IzzyOnDroid, we ship the "early birds": alpha &amp; beta versions.</p><p>Thanks to the hard work of the FlorisBoard team (thank you so much, Patrick &amp; lm41!), the app is finally RB!</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>(2/2)</p><p>And just 15 days before the first anniversary of our public RB GoLive (which happened on August 1st, 2024), we've reached 50% coverage:</p><p>Every 2nd app at IzzyOnDroid is now RB! 🥳</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
Hans-Christoph Steiner<p>Some <a href="https://social.librem.one/tags/Android" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Android</span></a> <a href="https://social.librem.one/tags/SDK" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SDK</span></a> packages are updated with a revision number, but <a href="https://social.librem.one/tags/sdkmanager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sdkmanager</span></a> does not allow installs to use that revision number. This sometimes breaks <a href="https://social.librem.one/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a>. There is an issue open since 2017 about this:<br><a href="https://issuetracker.google.com/issues/38045649" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">issuetracker.google.com/issues</span><span class="invisible">/38045649</span></a></p><p>If anyone wants this feature, it should be easy to implement in <a href="https://social.librem.one/tags/FDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FDroid</span></a>'s sdkmanager:<br><a href="https://gitlab.com/fdroid/sdkmanager/-/issues/26" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gitlab.com/fdroid/sdkmanager/-</span><span class="invisible">/issues/26</span></a></p>
mmu_man<p>Round of applause for Lunar who started <a href="https://m.g3l.org/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ReproducibleBuilds</span></a> at <a href="https://m.g3l.org/tags/Debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Debian</span></a> .</p><p><a href="https://m.g3l.org/tags/DebConf25" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DebConf25</span></a> <a href="https://m.g3l.org/tags/DebConf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DebConf</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, KeePassDX 🥳 </p><p>Both, the libre and the free flavor were just confirmed:</p><p><a href="https://apt.izzysoft.de/packages/com.kunzisoft.keepass.libre" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.k</span><span class="invisible">unzisoft.keepass.libre</span></a></p><p><a href="https://apt.izzysoft.de/packages/com.kunzisoft.keepass.free" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.k</span><span class="invisible">unzisoft.keepass.free</span></a></p><p>KeePassDX is a password safe and manager allows editing encrypted data in a single file in the open KeePass format and fill in the forms in a secure way, requires no Internet connection and integrates Android design standards.</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>June news at reproducible-builds.org have been released, stating IzzyOnDroid passed 48% coverage (48.8% now), and that <span class="h-card" translate="no"><a href="https://floss.social/@bg443" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bg443</span></a></span> made shields available to show the current RB status of an app. And on we go!</p><p><a href="https://reproducible-builds.org/reports/2025-06/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">reproducible-builds.org/report</span><span class="invisible">s/2025-06/</span></a></p><p><a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a> <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, OPN2 MIDI Player 🥳</p><p><a href="https://apt.izzysoft.de/packages/ru.wohlsoft.opnmidiplayer" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/ru.wo</span><span class="invisible">hlsoft.opnmidiplayer</span></a></p><p>OPN2 MIDI Player is a a MIDI-player based on emulator of a Frequency Modulation chip Yamaha OPN2 (YM2612).</p><p>With the help of its developer, we finally managed to confirm it as reproducible build, so its shield is up now :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB Family, Jerboa 🥳</p><p><a href="https://apt.izzysoft.de/packages/com.jerboa" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.j</span><span class="invisible">erboa</span></a></p><p>Jerboa is a client for Lemmy, made by Lemmy's developers. And Lemmy is the Fediverse alternative to Reddit, Lobste.rs, HN &amp; Co.</p><p>The current version finally passed RB, so the shield is up now!</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IzzyOnDroid</span></a></p>
Risotto Bias<p>pop quiz,</p><p>how do you know if the apps on your android phone are actually running the reproducible build you think they are,</p><p>under the trump admin.</p><p><a href="https://toot.risottobias.org/tags/android" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>android</span></a> <a href="https://toot.risottobias.org/tags/apk" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apk</span></a> <a href="https://toot.risottobias.org/tags/googlerecorder" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>googlerecorder</span></a> <a href="https://toot.risottobias.org/tags/apksigner" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apksigner</span></a> <a href="https://toot.risottobias.org/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproduciblebuilds</span></a></p>
IzzyOnDroid ✅<p><span class="h-card" translate="no"><a href="https://chaos.social/@SylvieLorxu" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>SylvieLorxu</span></a></span> sorry, but I had to boost this again now. <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>fdroidorg</span></a></span> can you please make optically clear which APKs you reproduced? Developers knock our doors wondering why we say their app is not RB, while you claim it is – and checking, EACH SINGLE TIME we find the app is NOT set up RB at your end, and the JSON at your verification server clearly states you verified YOUR OWN build. Yes, that might show your build is deterministic – but not that theirs is RB. It's confusing.</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>reproducibleBuilds</span></a></p>