[blog] 01/01: 121: explain that the policy work aint over yet
Holger Levsen
holger at layer-acht.org
Fri Aug 25 11:39:08 UTC 2017
This is an automated email from the git hooks/post-receive script.
holger pushed a commit to branch master
in repository blog.
commit ace71e96d9f8a6be49253067b0b1adf77b13e4a8
Author: Holger Levsen <holger at layer-acht.org>
Date: Fri Aug 25 13:39:05 2017 +0200
121: explain that the policy work aint over yet
Signed-off-by: Holger Levsen <holger at layer-acht.org>
---
drafts/121.mdwn | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drafts/121.mdwn b/drafts/121.mdwn
index 260775d..95f21e5 100644
--- a/drafts/121.mdwn
+++ b/drafts/121.mdwn
@@ -6,7 +6,8 @@ Reproducible Builds finally mandated by Debian Policy
-----------------------------------------------------
"Packages should build reproducibly" was [merged into Debian
-policy](https://anonscm.debian.org/git/dbnpolicy/policy.git/commit/?id=bf256860fbf9d7dccc05fe1aa85841b7a1b1d712)! The added text is as follows:
+policy](https://anonscm.debian.org/git/dbnpolicy/policy.git/commit/?id=bf256860fbf9d7dccc05fe1aa85841b7a1b1d712)! The added text is as follows and
+has been included into [debian-policy 4.1.0.0](https://tracker.debian.org/news/864773):
<pre>
Reproducibility
@@ -42,6 +43,7 @@ easier for packages to meet it.
briefly describing the background and implications of this, to quote him: "we are <i>not 94% done</i> yet, rather more like half done or so. We still need tools and processes to <i>enable anyone to indepently verify</i> that a given binary comes from the sources it is said to be coming, this will involve distributing <code>.buildinfo</code> files and providing user interfaces in APT and elsewhere. And probably also systematic rebuilds by us and other parties. And 6 or 7% of the archive [...]
* There were discussion threads on [Hacker News](https://news.ycombinator.com/item?id=15010438)
and [reddit](https://www.reddit.com/r/debian/comments/6touxc/new_debian_policy_packages_should_be_reproducible/).
+* Rather obviously, this is not yet what we really want to achieve, which is "packages <b>must</b> be reproducible" and then we also need to define things around <code>.buildinfo</code> files and more.
Reproducible work in other projects
-----------------------------------
--
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/reproducible/blog.git
More information about the Reproducible-commits
mailing list