.buildinfo
server
In order to build packages reproducibly, you not only need identical
sources but also some external definition of the environment used for a
particular build. This definition includes the inputs and the outputs
and—in the Debian case—are available in a
$package_$architecture_$version.buildinfo
file.
It is not currently clear how these files could or should be handled in practice, hence the creation of this server to investigate.
0x2EB7D8A099C83DD8
0x28F5F5D5FEE63ABA
0xFAC0B94FFF2617A2
cbxi4b (Automatically generated key for signing .buildinfo files)
0x58023F0702D8EEDD
0xAEC7FC78A3E8B530
0xCDD42D70685A0E01
0xFD20BBE472905784
0xB586FBCA67A0DDF7
0x5FA3DA39796FBACF
profitbricks-build1-amd64 (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0xBB1FD085171F6E18
profitbricks-build11-amd64 (Automatically generated key for signing .buildinfo files)
0xC58597F326D8D216
codethink-sled14-arm64 (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0xB42DAAC6B200534A
codethink-sled11-arm64 (Automatically generated key for signing .buildinfo files)
0xBB1FD085171F6E18
profitbricks-build11-amd64 (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0xFAC0B94FFF2617A2
cbxi4b (Automatically generated key for signing .buildinfo files)
0xCDD42D70685A0E01
0x28F5F5D5FEE63ABA
0x2EB7D8A099C83DD8
$ gpg --output=- --clearsign my.buildinfo | curl -X PUT --max-time 30 --data-binary @- https://buildinfo.debian.net/api/submit