Debian 14 cracks down on unreproducible packages

https://image.theregister.com/5238016.jpg?imageId=5238016&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Dull but important … so, a bit like Debian itself, really

About halfway through the Debian 14 “Forky” development process, itsrelease team announced a new goal: deterministic packagecompilation.

The Debian project’s latest Bitsfrom the release team newsletter has a goal which may not sound verybig, but will mean significant extra effort in a direction thatcould prove to be a valuable extra security measure.

"Aided by the efforts of the Reproducible Builds project,we’ve decided it’s time to say that Debian must ship reproduciblepackages," wrote ReleaseTeam member Paul Gevers. "Since yesterday, we have enabled our migration software toblock migration of new packages that can’t be reproduced orexisting packages (in testing) that regress in reproducibility."

Of the two links in that paragraph, the independent ReproducibleBuilds project does not, in this vulture’s humble opinion, explainwhat it’s all about very clearly. We feel that Debian’s own Reproducible Buildswiki page does it better:

It should...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more