.buildinfo
server
In order to build packages reproducibly, you not only need identical
sources but also some external definition of the environment used for a
particular build. This definition includes the inputs and the outputs
and—in the Debian case—are available in a
$package_$architecture_$version.buildinfo
file.
It is not currently clear how these files could or should be handled in practice, hence the creation of this server to investigate.
0xBFF95736F711C117
profitbricks-build15-amd64 (Automatically generated key for signing .buildinfo files)
0x5FA3DA39796FBACF
profitbricks-build1-amd64 (Automatically generated key for signing .buildinfo files)
0x1310D22166A88B5F
profitbricks-build6-i386 (Automatically generated key for signing .buildinfo files)
0xA6B59AB7CD69D4AC
profitbricks-build2-i386 (Automatically generated key for signing .buildinfo files)
0xF8139FC1C7D1A40B
codethink-sled9-arm64 (Automatically generated key for signing .buildinfo files)
0xC58597F326D8D216
codethink-sled14-arm64 (Automatically generated key for signing .buildinfo files)
0x9538881E43D098FB
jtx1b (Automatically generated key for signing .buildinfo files)
0x8FCA21099AC7DFA4
0xA6B59AB7CD69D4AC
profitbricks-build2-i386 (Automatically generated key for signing .buildinfo files)
0x1310D22166A88B5F
profitbricks-build6-i386 (Automatically generated key for signing .buildinfo files)
0x3B7B0B0B40A455E9
opi2a (Automatically generated key for signing .buildinfo files)
0x4AB633F00B2AAAA1
odxu4a (Automatically generated key for signing .buildinfo files)
0x00C8B57F4FD162BC
odu3a (Automatically generated key for signing .buildinfo files)
0x2BBA298F216A5729
ff64a (Automatically generated key for signing .buildinfo files)
0xAAA3AE5F86A5D0BA
codethink-sled13-arm64 (Automatically generated key for signing .buildinfo files)
0xC58597F326D8D216
codethink-sled14-arm64 (Automatically generated key for signing .buildinfo files)
0x5FA3DA39796FBACF
profitbricks-build1-amd64 (Automatically generated key for signing .buildinfo files)
0x1310D22166A88B5F
profitbricks-build6-i386 (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0xA6B59AB7CD69D4AC
profitbricks-build2-i386 (Automatically generated key for signing .buildinfo files)
$ gpg --output=- --clearsign my.buildinfo | curl -X PUT --max-time 30 --data-binary @- https://buildinfo.debian.net/api/submit