[blog] 01/01: 121: explain that the policy work aint over yet

Holger Levsen holger at layer-acht.org
Fri Aug 25 11:39:08 UTC 2017


This is an automated email from the git hooks/post-receive script.

holger pushed a commit to branch master
in repository blog.

commit ace71e96d9f8a6be49253067b0b1adf77b13e4a8
Author: Holger Levsen <holger at layer-acht.org>
Date:   Fri Aug 25 13:39:05 2017 +0200

    121: explain that the policy work aint over yet
    
    Signed-off-by: Holger Levsen <holger at layer-acht.org>
---
 drafts/121.mdwn | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drafts/121.mdwn b/drafts/121.mdwn
index 260775d..95f21e5 100644
--- a/drafts/121.mdwn
+++ b/drafts/121.mdwn
@@ -6,7 +6,8 @@ Reproducible Builds finally mandated by Debian Policy
 -----------------------------------------------------
 
 "Packages should build reproducibly" was [merged into Debian
-policy](https://anonscm.debian.org/git/dbnpolicy/policy.git/commit/?id=bf256860fbf9d7dccc05fe1aa85841b7a1b1d712)! The added text is as follows:
+policy](https://anonscm.debian.org/git/dbnpolicy/policy.git/commit/?id=bf256860fbf9d7dccc05fe1aa85841b7a1b1d712)! The added text is as follows and
+has been included into [debian-policy 4.1.0.0](https://tracker.debian.org/news/864773):
 
 <pre>
 Reproducibility
@@ -42,6 +43,7 @@ easier for packages to meet it.
   briefly describing the background and implications of this, to quote him: "we are <i>not 94% done</i> yet, rather more like half done or so. We still need tools and processes to <i>enable anyone to indepently verify</i> that a given binary comes from the sources it is said to be coming, this will involve distributing <code>.buildinfo</code> files and providing user interfaces in APT and elsewhere. And probably also systematic rebuilds by us and other parties. And 6 or 7% of the archive [...]
 * There were discussion threads on [Hacker News](https://news.ycombinator.com/item?id=15010438)
   and [reddit](https://www.reddit.com/r/debian/comments/6touxc/new_debian_policy_packages_should_be_reproducible/).
+* Rather obviously, this is not yet what we really want to achieve, which is "packages <b>must</b> be reproducible" and then we also need to define things around <code>.buildinfo</code> files and more.
 
 Reproducible work in other projects
 -----------------------------------

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/reproducible/blog.git



More information about the Reproducible-commits mailing list