@dolmen Many systems are based on #bootstrapping and #reproducableBuilds
https://bootstrappable.org/
https://reproducible-builds.org/
https://en.wikipedia.org/wiki/Bootstrapping_(compilers)

These ensure that the build system integrity cannot be tampered with. One example of such system is https://openbuildservice.org/

Here's a great read on the topic from #SUSE : https://documentation.suse.com/sbp/server-linux/html/SBP-SLSA4/

Generally Supply-chain Levels for Software Artifacts (#SLSA) framework is a great resource on this topic: https://slsa.dev/ #cybersecurity #infosec

Bootstrappable builds

So I admit a certain degree of #FOMO with #NixOS. I tried installing it via their #Plasma #ISO #distro and it crashed on the install. What's the best way to install Nix for a newb? I want to be able to build this glorious config file for #ReproducableBuilds but where do I start with that? Any help is appreciated.
At the moment Holger Levsen #Debian #reproducableBuilds talks about "Reproducible Builds, the first ten years" at the @fsfe 's track at #fossnorth
One thing I am clearly missing so far is cross server search. I am sure I am not the only one working with #Bazel or other build styems, or interested in #CI or #reproducableBuilds. But hosting yourself on a dedicated server kind of limits the search scope it seems. I wonder if this means that the desired model for Mastodon is to join large servers dedicated to specific topics.

@0
Is #Signal's apk build even reproducable?

Last we heard they proclaim to be #openSource but their build isn't reproducable and thus you don't **really** know the code you are running on your device when you are running it.

Doesn't it also use non-free network services?

#reproducableBuilds #floss #freeLicense

@Ayior @jcbrand