Welcome to the RB family, Synkplay πŸ₯³

https://apt.izzysoft.de/packages/com.reddnek.syncplay

Synkplay synchronizes playback on different devices and makes sure everyone is watching the same thing at the same second, even if they're miles away.

Thanks to the help of its developer, we finally succeeded with #ReproducibleBuilds for it at the #IzzyOnDroid repository 

β€žSynkplayβ€œ – IzzyOnDroid F-Droid Repository

synchronize media playback (video/audio) on multiple devices

IzzyOnDroid Repo Browser

Aaand… Welcome to the RB family, Sshd4a πŸ₯³

https://apt.izzysoft.de/packages/com.hardbacknutter.sshd

Sshd4a provides an 'sshd' server with shell access, rsync and scp/sftp services. Thanks to the help of its developer, it could now be confirmed to be reproducible 

Coming to your favourite repository with the next sync πŸ˜‰

#IzzyOnDroid #ReproducibleBuilds

β€žSshd4aβ€œ – IzzyOnDroid F-Droid Repository

An 'sshd' server with shell access, rsync and scp/sftp services.

IzzyOnDroid Repo Browser

Inspired by the Debian 14 announcement, I’ve finally made my json-store #Python package create reproducible builds.

This was super easy thanks to all the work done by the hatch build system.

https://hatch.pypa.io/1.16/config/build/#reproducible-builds

You should too. 😁

#reproduciblebuilds

Build configuration - Hatch

Modern, extensible Python project management

Dear opensource developers,

I added an "adoption" list to the repro-env README, if you publish pre-compiled binaries and you successfully adopted it to allow anyone to reproduce them from source code to prove the absense of a build server compromise, you are very welcome to add yourself to the list. 😺

https://github.com/kpcyrd/repro-env#adoption

#reproducible #reproduciblebuilds #supplychainsecurity #rust

GitHub - kpcyrd/repro-env: Dependency lockfiles for reproducible build environments πŸ“¦πŸ”’

Dependency lockfiles for reproducible build environments πŸ“¦πŸ”’ - kpcyrd/repro-env

GitHub

Debian 14 Forky is mandating bit-for-bit identical builds to stop supply chain attacks. Discover how this shifts trust from servers to auditable source code.

More details here: https://ostechnix.com/debian-linux-reproducible-builds/

#Debian14 #DebianForky #ReproducibleBuilds #Security #Linux #Packages #SupplyChainSecurity

Debian 14 Forky Mandates Reproducible Builds for Security - OSTechNix

Debian 14 Forky is mandating bit-for-bit identical builds to stop supply chain attacks. Discover how this shifts trust from servers to auditable source code.

OSTechNix

Hey #Google, cool you're adding a bit of #BinaryTransparency. Unfortunately, it doesn't mean much without #FreeSoftware #OpenSource and #ReproducibleBuilds. When can we expect you to adopt those practices?

https://blog.google/security/bringing-binary-transparency-to-the-android-ecosystem/

For the record #FDroid has offered binary transparency since 2017 https://gitlab.com/fdroid/fdroidserver/-/merge_requests/226

And we even offer binary transparency for your #Gradle and #AndroidSDK binaries
https://f-droid.org/2021/02/05/apis-for-all-the-things.html#binary-transparency-logs

How about expanding your logging to all your binaries?

Evolving Verifiable Trust: Bringing Binary Transparency to the Android Ecosystem

Google is expanding Binary Transparency on Android to help you verify that your Google apps are genuine and authorized for release.

Google
Wow, nice status for the #ReproducibleBuilds at #IzzyOnDroid today – 888 apps (64.9%) 

Debian's mandate for reproducible packages aims to revolutionize software supply chain security, but the real challenge extends far beyond verifying source code. The article explains how achieving byte-for-byte identical binaries requires meticulously neutralizing every source of non-determinism across the entire build toolchain and package ecosystem, a formidable engineering feat for a…

https://www.tpp.blog/1d23ahl

#cybersecurity #debian #reproduciblebuilds

πŸ€– This post was AI-generated.

Why Reproducible Builds?

μž¬ν˜„ κ°€λŠ₯ν•œ λΉŒλ“œ(reproducible builds)λŠ” λΉŒλ“œ ν™˜κ²½μ΄λ‚˜ μ»΄νŒŒμΌλŸ¬κ°€ μ•…μ˜μ μœΌλ‘œ λ³€μ‘°λ˜μ—ˆλŠ”μ§€ 쑰기에 탐지할 수 있게 ν•˜μ—¬ λ³΄μ•ˆ 곡격에 λŒ€μ‘ν•œλ‹€. λ˜ν•œ, λ‹€μ–‘ν•œ ν™˜κ²½μ—μ„œμ˜ μΌκ΄€λœ λΉŒλ“œ ν…ŒμŠ€νŠΈλ₯Ό 톡해 ν’ˆμ§ˆ 보증과 디버깅을 μš©μ΄ν•˜κ²Œ ν•˜λ©°, λ°”μ΄λ„ˆλ¦¬ 차이λ₯Ό μ΅œμ†Œν™”ν•΄ μ €μž₯ 곡간과 λ„€νŠΈμ›Œν¬ λΉ„μš©μ„ μ ˆκ°ν•œλ‹€. 개발 속도 ν–₯상과 μ˜μ‘΄μ„± 투λͺ…μ„± 확보, μ†Œν”„νŠΈμ›¨μ–΄ ꡬ성 μš”μ†Œ λͺ©λ‘(SBOM) 생성에도 κΈ°μ—¬ν•˜μ—¬ λ³΄μ•ˆκ³Ό 규제 μ€€μˆ˜μ— ν•„μˆ˜μ μ΄λ‹€. μ—νŽ˜λ©”λž„ 개발 ν™˜κ²½κ³Ό κ²°ν•©ν•˜λ©΄ μ‹ μ†ν•œ ν™˜κ²½ μž¬ν˜„κ³Ό λ³΄μ•ˆ κ°•ν™”κ°€ κ°€λŠ₯ν•΄ ν˜„λŒ€ DevSecOps μ‹€μ²œμ— μ ν•©ν•˜λ‹€.

https://reproducible-builds.org/docs/why/

#reproduciblebuilds #security #softwaredevelopment #sbom #devsecops

Why reproducible builds? β€” reproducible-builds.org

Debian alza l'asticella della sicurezza rendendo obbligatorie le "Reproducible Builds" per Debian 14 "Forky".
Ogni pacchetto dovrΓ  poter essere ricompilato partendo dal sorgente originale pena la sua esclusione.
Questo garantisce che il software che installiamo sia esattamente quello dichiarato dagli sviluppatori, proteggendoci da manipolazioni durante la fase di compilazione.
https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/

@linux

#Debian #Linux #Sicurezza #ReproducibleBuilds #SoftwareLibero #Privacy