Reproducible Builds

This cluster discusses the concept of reproducible builds, their importance for verifying software integrity and security, challenges in implementation, and related tools/projects like those from Debian and Nix.

➡️ Stable 0.8x Security
2,930
Comments
17
Years Active
5
Top Authors
#3549
Topic ID

Activity Over Time

2009
1
2010
2
2011
1
2013
33
2014
49
2015
108
2016
204
2017
227
2018
127
2019
259
2020
260
2021
382
2022
233
2023
312
2024
311
2025
411
2026
10

Keywords

CI FOSDEM2014 nixos.org FWIW BTW i.e fosdem.org RFC GNU ReproducibleBuilds reproducible builds binary build app stores source nix deterministic app verify

Sample Comments

Reproducible builds are not as widespread as you'd imagine: https://en.wikipedia.org/wiki/Reproducible_builds

feanaro Jan 9, 2022 View on HN

The term you're looking for is reproducible builds and it's unfortunately not trivial and a somewhat rare state of affairs. It's definitely crucial in the long run.

gary_0 Mar 17, 2022 View on HN

Reproducible builds are important as well.

pabs3 Aug 27, 2019 View on HN

More info about reproducible builds is here:https://reproducible-builds.org/

pabs3 May 13, 2022 View on HN

I hope the things being built with this are reproducible.https://reproducible-builds.org/

fsflover May 19, 2025 View on HN

There's reproducible builds project for that. (Except too few people will know how to actually verify it.)

indolering Oct 18, 2019 View on HN

There are security reasons to want a reproducible build.

dec0dedab0de May 6, 2025 View on HN

you don't, that is what reproducible builds are trying to solve, but even then it would still need someone to compile and check.https://en.wikipedia.org/wiki/Reproducible_builds

tetris11 Sep 28, 2024 View on HN

If builds are reproducible, what's the issue?

forgotpwd16 Apr 23, 2021 View on HN

I believe what you're looking for is https://reproducible-builds.org.