> I"m not sure if many other projects do like Guix and record the checksum of the whole repository so as to ensure reproducibility purely from source.
If the packager chooses to use the official tarball as "the source", validating the checksum would not have helped. :-( Also whether it's always possible to run running autoreconf depends on the content of the tarball.
Which brings me to the (preliminary) conclusion that we'd better use repos as source of trust @lispi314@AndresFreundTec@glyph
Wie Ihr sicher mitbekommen habt, hat Zoom dieses Jahr einen #BigBrotherAward bekommen: https://bigbrotherawards.de/2023/zoom. Eigentlich ging der Negativpreis allerdings an z.B. Euch, die Ihr Eure Förderinnen nötigt, auf ihre Grundrechte zu verzichten.