.buildinfo
server
In order to build packages reproducibly, you not only need identical
sources but also some external definition of the environment used for a
particular build. This definition includes the inputs and the outputs
and—in the Debian case—are available in a
$package_$architecture_$version.buildinfo
file.
It is not currently clear how these files could or should be handled in practice, hence the creation of this server to investigate.
0xBFF95736F711C117
profitbricks-build15-amd64 (Automatically generated key for signing .buildinfo files)
0x1D3EA4D86F2FB555
codethink-sled15-arm64 (Automatically generated key for signing .buildinfo files)
0xFDD087C6FCA6B1BE
codethink-sled10-arm64 (Automatically generated key for signing .buildinfo files)
0xC58597F326D8D216
codethink-sled14-arm64 (Automatically generated key for signing .buildinfo files)
0x1D3EA4D86F2FB555
codethink-sled15-arm64 (Automatically generated key for signing .buildinfo files)
0x2BBA298F216A5729
ff64a (Automatically generated key for signing .buildinfo files)
0xBB1FD085171F6E18
profitbricks-build11-amd64 (Automatically generated key for signing .buildinfo files)
0xFAC0B94FFF2617A2
cbxi4b (Automatically generated key for signing .buildinfo files)
0xBFF95736F711C117
profitbricks-build15-amd64 (Automatically generated key for signing .buildinfo files)
0x4AB633F00B2AAAA1
odxu4a (Automatically generated key for signing .buildinfo files)
0xA7B82CF0C0043589
jtx1a (Automatically generated key for signing .buildinfo files)
0x2BBA298F216A5729
ff64a (Automatically generated key for signing .buildinfo files)
0x33C61B5B15DE238B
0x8FCA21099AC7DFA4
0x2BBA298F216A5729
ff64a (Automatically generated key for signing .buildinfo files)
0xF8139FC1C7D1A40B
codethink-sled9-arm64 (Automatically generated key for signing .buildinfo files)
0xC58597F326D8D216
codethink-sled14-arm64 (Automatically generated key for signing .buildinfo files)
0x1310D22166A88B5F
profitbricks-build6-i386 (Automatically generated key for signing .buildinfo files)
0xA6B59AB7CD69D4AC
profitbricks-build2-i386 (Automatically generated key for signing .buildinfo files)
0x1310D22166A88B5F
profitbricks-build6-i386 (Automatically generated key for signing .buildinfo files)
$ gpg --output=- --clearsign my.buildinfo | curl -X PUT --max-time 30 --data-binary @- https://buildinfo.debian.net/api/submit