.buildinfo
server
In order to build packages reproducibly, you not only need identical
sources but also some external definition of the environment used for a
particular build. This definition includes the inputs and the outputs
and—in the Debian case—are available in a
$package_$architecture_$version.buildinfo
file.
It is not currently clear how these files could or should be handled in practice, hence the creation of this server to investigate.
0x1D3EA4D86F2FB555
codethink-sled15-arm64 (Automatically generated key for signing .buildinfo files)
0x192E42C740CBB29A
codethink-sled12-arm64 (Automatically generated key for signing .buildinfo files)
0xFDD087C6FCA6B1BE
codethink-sled10-arm64 (Automatically generated key for signing .buildinfo files)
0xF8139FC1C7D1A40B
codethink-sled9-arm64 (Automatically generated key for signing .buildinfo files)
0xBB1FD085171F6E18
profitbricks-build11-amd64 (Automatically generated key for signing .buildinfo files)
0xBFF95736F711C117
profitbricks-build15-amd64 (Automatically generated key for signing .buildinfo files)
0xA7B82CF0C0043589
jtx1a (Automatically generated key for signing .buildinfo files)
0x1933B8D8B28A65EB
cb3a (Automatically generated key for signing .buildinfo files)
0x2BBA298F216A5729
ff64a (Automatically generated key for signing .buildinfo files)
0xFAC0B94FFF2617A2
cbxi4b (Automatically generated key for signing .buildinfo files)
0x4AB633F00B2AAAA1
odxu4a (Automatically generated key for signing .buildinfo files)
0x5FA3DA39796FBACF
profitbricks-build1-amd64 (Automatically generated key for signing .buildinfo files)
0x00C8B57F4FD162BC
odu3a (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0xBFF95736F711C117
profitbricks-build15-amd64 (Automatically generated key for signing .buildinfo files)
0x5FA3DA39796FBACF
profitbricks-build1-amd64 (Automatically generated key for signing .buildinfo files)
0x3790BB94D873CF00
p64c (Automatically generated key for signing .buildinfo files)
0x8FCA21099AC7DFA4
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
0x1BD40F376E003684
profitbricks-build5-amd64 (Automatically generated key for signing .buildinfo files)
$ gpg --output=- --clearsign my.buildinfo | curl -X PUT --max-time 30 --data-binary @- https://buildinfo.debian.net/api/submit