You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reproducible builds are important as they provide an independently-verifiable path from source to binary code (ref).
The goreleaser configuration follows some of the recommendations for reproducible builds available here. We do not currently make use of the -trimpath flag, though arguably formal releases are always built by continuous integration, and thus use a consistent directory structure.
On the other hand the mage build is not currently reproducible, as demonstrated by running the build twice from the same commit:
Reproducible builds are important as they provide an independently-verifiable path from source to binary code (ref).
The
goreleaser
configuration follows some of the recommendations for reproducible builds available here. We do not currently make use of the-trimpath
flag, though arguably formal releases are always built by continuous integration, and thus use a consistent directory structure.On the other hand the
mage
build is not currently reproducible, as demonstrated by running the build twice from the same commit:I think it might make sense to make the
siftool
build reproducible, and unify the build flags used betweengoreleaser
andmage
.The text was updated successfully, but these errors were encountered: