There was a bunch of activity around Reproducible Builds at #FOSDEM! A 🧵...
On the main stage, core #ReproducibleBuilds dev Holger 'h01ger' Levsen presented "Titled Reproducible Builds: The First Ten Years" giving an overview: how it started with a small BoF at DebConf13 (and before), then grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an Executive Order of the President of the United States.
"RISC-V Bootstrapping in Guix and Live-Bootstrap" was presented by @ekaitz_zarraga in the "Declarative and Minimalistic Computing" devroom, mentioning GNU Mes, TinyCC, GCC, live-bootstrap, GNU #Guix and other related projects.
@malte and @katexochen presented "Reproducible builds for confidential computing: Why remote attestation is worthless without it" in the Confidential Computing devroom, covering the status quo of how reference values are used in CC. Based on a minimal open source example, they explained how they build fully reproducible OS images with mkosi and #NixOS - all the way from source code in Git to the reference values for remote attestation.
set of software development practices that create an independently-verifiable path from source code to the binary code used by computers.Account monitored by @raboof