[Git][reproducible-builds/reproducible-website][master] 2026-06: Initial draft
Chris Lamb (@lamby)
gitlab at salsa.debian.org
Thu Jul 9 21:29:29 UTC 2026
Chris Lamb pushed to branch master at Reproducible Builds / reproducible-website
Commits:
e2c9acb5 by Chris Lamb at 2026-07-09T14:28:59-07:00
2026-06: Initial draft
- - - - -
15 changed files:
- _reports/2026-06.md
- bin/generate-draft.template
- + images/reports/2026-06/1-s2.0-S2405959526001086-main.png
- + images/reports/2026-06/2025-nixpkgs-reproducibility-extended.png
- + images/reports/2026-06/DSN-HAP26_muto.png
- + images/reports/2026-06/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.png
- + images/reports/2026-06/debian-lg.png
- + images/reports/2026-06/debian.png
- + images/reports/2026-06/diffoscope.png
- + images/reports/2026-06/fedora.png
- + images/reports/2026-06/opensuse.png
- + images/reports/2026-06/repro-threshold.png
- + images/reports/2026-06/reproduce.debian.net.png
- + images/reports/2026-06/reproducible-builds.png
- + images/reports/2026-06/website.png
Changes:
=====================================
_reports/2026-06.md
=====================================
@@ -6,32 +6,202 @@ title: "Reproducible Builds in June 2026"
draft: true
---
-* [FIXME](https://hal.science/hal-05630285v1/file/2025-nixpkgs-reproducibility-extended.pdf)
-* [FIXME](https://github.com/keszybz/add-determinism/pull/78)
-* [FIXME, WIP, demo](https://rebuilderd.n.aparcar.org/)
-* [FIXME](https://rebuilderd.xpam.pl:2096/demo.html)
+**Welcome to the June 2026 report from the [Reproducible Builds](https://reproducible-builds.org) project!**
+{: .lead}
-* [FIXME](https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf)
-* FIXME: the fix for [JDK-8385738](https://bugs.openjdk.org/projects/JDK/issues/JDK-8385738?filter=allissues) linking to [https://reproduce.debian.net/all/api/v1/builds/206100/artifacts/426780/diffoscope](https://reproduce.debian.net/all/api/v1/builds/206100/artifacts/426780/diffoscope) was uploaded to Debian unstable for openjdk(25|26|27) - see
- https://tracker.debian.org/news/1760093/accepted-openjdk-27-2724ea-2-source-into-unstable/ and
- https://tracker.debian.org/news/1760960/accepted-openjdk-26-26018-3-source-into-unstable/
- https://tracker.debian.org/news/1760962/accepted-openjdk-25-25044ea-1-source-into-unstable/
+[](https://reproducible-builds.org/)
-* FIXME: the reproduce.debian.net reason-pages (like https://reproduce.debian.net/ppc64el/stats/unstable/) now also contain
- links labeled 🐛 linking to the categorized issues packages have been tagged with via reproducible-notes.git
+In these reports, we outline the most important things that we have been up to over the past month. As a quick recap about what problem our project intends to solve, whilst anyone may inspect the source code of free software for malicious flaws, almost all software is distributed to end users as pre-compiled binaries. The motivation behind the reproducible builds effort is to ensure no flaws have been introduced during this compilation process by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a build was compromised or not.
-* [FIXME](https://devguard.org/research-development/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.pdf)
+If you are interested in contributing to the project, please visit our [*Contribute*]({{ "/contribute/" | relative_url }}) page on our website.
-* [FIXME](https://www.sciencedirect.com/science/article/pii/S2405959526001086)
+<!--
+In this month's report, we cover:
-* [openSUSE monthly](https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/LQPMRQ5W3XJ7RWAQ6ITI4EY2EDVTVHKA/)
+0. Automatically generated prior to publication.
+-->
+
+---
+
+<br>
+
+### Only installing reproducible packages with *repro-threshold*
+
+[](https://rebuilderd.xpam.pl:2096/demo.html)
+
+A [very interesting demonstration](https://rebuilderd.xpam.pl:2096/demo.html) is now available showing how you might configure your Debian system to only install packages that have been reproduced by *m/n* rebuilders.
+
+This is implemented via a `reproduced+https://` [APT](https://en.wikipedia.org/wiki/APT_(software)) transport ( a mechanism for communicating between the APT client and its repository source — commonly HTTP):
+
+> Every package download is intercepted by `repro-threshold`, which queries two independent rebuilders for a signed attestation before allowing installation to proceed. [It] is important to note that [an] install will only succeed if all package dependencies are also reproducible.
+
+The [demo](https://rebuilderd.xpam.pl:2096/demo.html) gives examples of how to quickly experiment with this using a [Docker](https://www.docker.com/) container.
+
+<br>
+
+### Distribution work
+
+[](https://debian.org/)
+
+In **Debian** this month:
+
+* The [`debian-installer`](https://tracker.debian.org/pkg/debian-installer) package in Debian was uploaded with a [substantial reproducibility-related changelog](https://tracker.debian.org/news/1768824/accepted-debian-installer-20260628-source-into-unstable/). This means, for the first time, the [uploaded version could finally be reproduced](https://reproduce.debian.net/excuses.html?source_name=debian-installer).
+
+* Various [OpenJDK](https://openjdk.org/) packages were also uploaded to Debian, including the fix for `JDK-8385738` ("Javadoc does not produce reproducible output…") ([for example](https://reproduce.debian.net/all/api/v1/builds/206100/artifacts/426780/diffoscope)). [[...](https://tracker.debian.org/news/1760093/accepted-openjdk-27-2724ea-2-source-into-unstable/)][[...](https://tracker.debian.org/news/1760960/accepted-openjdk-26-26018-3-source-into-unstable/)][[...](https://tracker.debian.org/news/1760962/accepted-openjdk-25-25044ea-1-source-into-unstable/)]
+
+* The "reason" pages on [*reproduce.debian.net*](https://reproduce.debian.net), [such as the one for *ppc64el*](https://reproduce.debian.net/ppc64el/stats/unstable/), now feature links labeled with the [bug emoji](https://www.compart.com/en/unicode/U+1F41B) (i.e. 🐛) which links to the categorized issues packages have been tagged with in the `reproducible-notes.git` repo.
+
+* Indeed, 25 reviews of Debian packages were added, 31 were updated and 33 were removed this month adding to [our extensive knowledge about identified issues](https://tests.reproducible-builds.org/debian/index_issues.html). Two issue types were updated as well. [[...](https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/a2302451)][[...](https://salsa.debian.org/reproducible-builds/reproducible-notes/commit/9e09f1ee)]
+
+[](https://www.opensuse.org/)
+
+In addition, Bernhard M. Wiedemann posted another [**openSUSE**](https://www.opensuse.org/) [monthly update](https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/thread/LQPMRQ5W3XJ7RWAQ6ITI4EY2EDVTVHKA/) for their reproducibility work there.
+
+<br>
+
+### *diffoscope* development
+
+[](https://diffoscope.org/)
+
+[**diffoscope**](https://diffoscope.org) is our in-depth and content-aware diff utility that can locate and diagnose reproducibility issues. This month, Chris Lamb made the following changes, including preparing and uploading versions [319](https://tracker.debian.org/news/1762589/accepted-diffoscope-319-source-into-unstable/), [320](https://tracker.debian.org/news/1764827/accepted-diffoscope-320-source-into-unstable/), [321](https://tracker.debian.org/news/1764860/accepted-diffoscope-321-source-into-unstable/), [322](https://tracker.debian.org/news/1767978/accepted-diffoscope-322-source-into-unstable/) and [323](https://tracker.debian.org/news/1769647/accepted-diffoscope-323-source-into-unstable/) to Debian:
+
+* Debian adds an extra `Flags:` line in the output of `ocamlobjinfo`, so adjust the test for cross-distribution compatibility. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/3a2303e5)]
+* Bump debhelper compatibility level to 14. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/ae1d587a)]
+* Fix compatibility with Ocaml 5.4.1. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/50476c66)]
+* Use `--long-form`-style arguments when calling `apktool` in order to support *apktool* version 3. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/02c65572)]
+* Support Androguard version 4 and previous versions at the same time. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/2b17885b)]
+* Update copyright years. [[…](https://salsa.debian.org/reproducible-builds/diffoscope/commit/bf7aa877)]
+
+In addition, Jochen Sprickerhof added better header detection for the [Sphinx documentation system](https://www.sphinx-doc.org/en/master/) [[...](https://salsa.debian.org/reproducible-builds/diffoscope/commit/b800d697)], Michael Daniels fixed the tests when run with *zipdetails* version 4.006 [[...](https://salsa.debian.org/reproducible-builds/diffoscope/commit/fade8d04)] and Zbigniew Jędrzejewski-Szmek added a version of the deprecated `os.path.commonprefix` method [[...](https://salsa.debian.org/reproducible-builds/diffoscope/commit/2af9e134)].
+
+<br>
+
+Chris Lamb also made the following changes to *[strip-nondeterminism](https://tracker.debian.org/pkg/strip-nondeterminism)*, our tool to remove specific non-deterministic results from a completed build:
+
+* Skip symlinks when manually called via `/usr/bin/strip-nondeterminism`. ([#1139000](https://bugs.debian.org/1139000))
+* Update `debian/watch` format. [[…](https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/9042813)]
+* Drop `Rules-Requires-Root: no` and `Priority: optional` fields. [[…](https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/7399bc4)]
+* Bump `Standards-Version` to version 4.7.4. [[…](https://salsa.debian.org/reproducible-builds/strip-nondeterminism/commit/aa3e692)]
+
+<br>
+
+### From our mailing list…
+
+On [our mailing list](https://lists.reproducible-builds.org/listinfo/rb-general/) this month:
+
+* *kpcyrd* posted to our mailing list regarding the "waves of malware uploads to [aur.archlinux.org](https://aur.archlinux.org/)". Curiously, "every incident I looked at used npmjs.com for malware delivery", specifically where the `npm` package includes an (automatically executed) `preinstall` script that is an ELF binary.
+
+* *kpcyrd* also announced the release of [*debian-repro-status*](https://github.com/kpcyrd/debian-repro-status) version [0.4.0](https://github.com/kpcyrd/debian-repro-status/releases/tag/v0.4.0), a tool written "to give you an approximate idea of how viable it would be to enforce a 'reproducible packages only' update policy for the computer system you've built":
+
+ > The change updates dependencies to the latest versions, and adds support for multiple `-H` options, to query results from multiple rebuilderd instances. The results are also now fetched concurrently.
+
+* *kpcyrd* also reported that, whilst taking a screenshot for the above release, they noticed that the `debian:sid` [container now is 100% reproducible](https://lists.reproducible-builds.org/pipermail/rb-general/2026-June/004121.html).
+
+* Finally, *kpcyrd* **also** [created a pull request](https://github.com/keszybz/add-determinism/pull/78) against the [*add-determinism*](https://github.com/keszybz/add-determinism) package to update the [`itertools`](https://docs.python.org/3/library/itertools.html) and [`zip`](https://docs.python.org/3/library/zipfile.html) Python dependencies.
+
+<br>
+
+### Documentation updates
+
+[]({{ "/" | relative_url }})
+
+Yet again, there were a number of improvements made to our website this month including:
+
+* Chris Lamb added a reminder re. using the UTC variants of the Javascript `Date` methods. [[…](https://salsa.debian.org/reproducible-builds/reproducible-website/commit/27245b53)]
+
+* Mattia Rizzolo moved [OTF](https://www.opentech.fund/) to the 'old' sponsors list. Thank you for your support!. [[...](https://salsa.debian.org/reproducible-builds/reproducible-website/commit/d029630d)]
+
+* *kpcyrd* updated the [Rust](https://rust-lang.org/) documentation to recommend using the `--release` argument for consistency. [[...](https://salsa.debian.org/reproducible-builds/reproducible-website/commit/f5d645e5)]
+
+<br>
+
+### Patches
+
+The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where applicable or possible. This month, we wrote a large number of such patches, including:
* Bernhard M. Wiedemann:
- * [`efl`](https://build.opensuse.org/request/show/1362390) (race)
- * [`plasma6-keyboard`](https://build.opensuse.org/request/show/1362888) (Qt-rcc race)
- * [`cvise`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268265) (FTBFS-j1)
- * [`hadrian`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268340) (FTBFS-cpu)
- * [`gettext-runtime/bash`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268542) (toolchain date)
- * [`syntax-highlighting`](https://invent.kde.org/frameworks/syntax-highlighting/-/merge_requests/806) (date)
-
-* [FIXME:src:debian-installer was finally uploaded with a massive rb related changelog](https://tracker.debian.org/news/1768824/accepted-debian-installer-20260628-source-into-unstable/) so that for a first time the [uploaded version could finally be reproduced](https://reproduce.debian.net/excuses.html?source_name=debian-installer)
+
+ * [`cvise`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268265)
+ * [`efl`](https://build.opensuse.org/request/show/1362390)
+ * [`gettext-runtime/bash`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268542)
+ * [`hadrian`](https://bugzilla.opensuse.org/show_bug.cgi?id=1268340)
+ * [`plasma6-keyboard`](https://build.opensuse.org/request/show/1362888)
+ * [`syntax-highlighting`](https://invent.kde.org/frameworks/syntax-highlighting/-/merge_requests/806)
+
+* Chris Lamb:
+
+ * [#1139654](https://bugs.debian.org/1139654) filed against [`node-fuse.js`](https://tracker.debian.org/pkg/node-fuse.js).
+ * [#1139655](https://bugs.debian.org/1139655) filed against [`node-egjs-hammerjs`](https://tracker.debian.org/pkg/node-egjs-hammerjs).
+ * [#1139656](https://bugs.debian.org/1139656) filed against [`node-chartjs-adapter-date-fns`](https://tracker.debian.org/pkg/node-chartjs-adapter-date-fns).
+ * [#1139662](https://bugs.debian.org/1139662) filed against [`mkdocs-include-markdown-plugin`](https://tracker.debian.org/pkg/mkdocs-include-markdown-plugin).
+ * [#1139704](https://bugs.debian.org/1139704) filed against [`lmarbles`](https://tracker.debian.org/pkg/lmarbles).
+ * [#1140240](https://bugs.debian.org/1140240) filed against [`rocm-docs-core`](https://tracker.debian.org/pkg/rocm-docs-core).
+ * [#1140567](https://bugs.debian.org/1140567) filed against [`libecoli`](https://tracker.debian.org/pkg/libecoli).
+ * [#1140688](https://bugs.debian.org/1140688) filed against [`golang-github-tobischo-gokeepasslib`](https://tracker.debian.org/pkg/golang-github-tobischo-gokeepasslib).
+
+* Jochen Sprickerhof:
+
+ * [#1139457](https://bugs.debian.org/1139457) filed against [`c-munipack`](https://tracker.debian.org/pkg/c-munipack).
+ * [#1140365](https://bugs.debian.org/1140365) filed against [`latex-coffee-stains`](https://tracker.debian.org/pkg/latex-coffee-stains).
+ * [#1140366](https://bugs.debian.org/1140366) filed against [`cxxtest`](https://tracker.debian.org/pkg/cxxtest).
+ * [#1140367](https://bugs.debian.org/1140367) filed against [`slime`](https://tracker.debian.org/pkg/slime).
+ * [#1140368](https://bugs.debian.org/1140368) filed against [`spooles`](https://tracker.debian.org/pkg/spooles).
+ * [#1140369](https://bugs.debian.org/1140369) filed against [`sdpb`](https://tracker.debian.org/pkg/sdpb).
+ * [#1140645](https://bugs.debian.org/1140645) filed against [`procmail`](https://tracker.debian.org/pkg/procmail).
+ * [#1140676](https://bugs.debian.org/1140676) filed against [`proftpd-dfsg`](https://tracker.debian.org/pkg/proftpd-dfsg).
+ * [#1141059](https://bugs.debian.org/1141059) filed against [`mah-jong`](https://tracker.debian.org/pkg/mah-jong).
+ * [#1141133](https://bugs.debian.org/1141133) filed against [`dxf2gcode`](https://tracker.debian.org/pkg/dxf2gcode).
+ * [#1141194](https://bugs.debian.org/1141194) filed against [`afterstep`](https://tracker.debian.org/pkg/afterstep).
+ * [#1141195](https://bugs.debian.org/1141195) filed against [`ledger2beancount`](https://tracker.debian.org/pkg/ledger2beancount).
+ * [#1141196](https://bugs.debian.org/1141196) filed against [`ocamlviz`](https://tracker.debian.org/pkg/ocamlviz).
+
+* Kris Van Hees:
+
+ * [#1140167](https://bugs.debian.org/1140167) filed against [`dtrace`](https://tracker.debian.org/pkg/dtrace).
+
+<br>
+
+### Four new scholarly papers
+
+[](https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf)
+
+Kenichiro Muto and Kuniyasu Suzaki of the [Institute of Information Security](https://www.iisec.ac.jp/english/) in Yokohama, Japan published an interesting paper this month titled [*Attestable Build Chain: Enabling Trust in Reproducible Builds*](https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf) (PDF). Their abstract is as follows:
+
+Ensuring trust in software supply chains requires verifying not only artifacts but also the processes that produce them. Although Reproducible Builds (R-B) require rebuilding to validate artifacts, they cannot verify whether the build was executed with the intended toolchain and inputs and may reproduce unintended or compromised builds without detection. We present Attestable Build Chain, a framework for externally verifying build-time execution without rebuilding. Rather than preventing compromise, it provides verifiable, tamper-evident evidence of actual build-time execution, enabling verification of build process integrity from observed file accesses during the build. [[...](https://lab.iisec.ac.jp/~suzaki_lab/PDF/DSN-HAP26_muto.pdf)]
+
+<br>
+
+[](https://hal.science/hal-05630285v1)
+
+Julien Malka, Stefano Zacchiroli and Théo Zimmermann published a 50-page report detailing [*A Decade of Software Reproducibility in the Nix Package Ecosystem*](https://hal.science/hal-05630285v1):
+
+> We find that functional package management enables extremely high rebuildability over time (**near-universal ability to reconstitute historical build environments and rebuild software packages**), while bitwise reproducibility has steadily improved and reaches a high point in recent years (up to 93% in 2024). Early years show substantially lower bitwise reproducibility, indicating that functional package management alone does not guarantee bitwise-identical outputs, and that the observed high level of bitwise reproducibility is not solely due to the package management approach. Common causes of unreproducibility, both in the rebuildability and bitwise reproducibility dimensions, include management of dates in build and test processes; we quantify their prevalence and other common causes using manual analysis of logs of rebuild failures and automated analysis of [*diffoscope*](https://diffoscope.org/).
+
+A [PDF of their report](https://hal.science/hal-05630285v1/file/2025-nixpkgs-reproducibility-extended.pdf) is available online
+
+<br>
+
+[](https://devguard.org/research-development/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.pdf)
+
+Tim Bastin of [L3montree GmbH](https://l3montree.com/) and Jacek Galowicz of [Applicative Systems GmbH](https://applicative.systems/) from [DevGuard](https://devguard.org/) published a paper detailing [*How We Built a Sovereign, Reproducible Container Supply Chain for DevGuard*](https://devguard.org/research-development/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.pdf):
+
+> This paper presents how the [DevGuard](https://devguard.org/) project rebuilt its [OCI container](https://opencontainers.org/) pipeline around reproducible [Nix](https://nixos.org/) builds and independent dual-platform digest verification. DevGuard images are built hermetically from pinned source revisions, signed with [Sigstore/Cosign](https://github.com/sigstore/cosign), and verified through digest comparison across GitHub Actions and sovereign GitLab infrastructure hosted on container.gov.de. We describe the practical integration of reproducible OCI image builds into existing CI/CD workflows and argue that independently reproducible container digests provide a stronger integrity guarantee against build tampering than provenance alone. The paper further discusses remaining trust assumptions and the relevance of sovereign build infrastructure for government and regulated environments.
+
+<br>
+
+[](https://www.sciencedirect.com/science/article/pii/S2405959526001086)
+
+Finally, Yiseul Choi, Junga Kim, Jun-Ho Hong and Seongmin Kim of the [Department of Convergence Security Engineering](https://www.sungshin.ac.kr/main_eng/15348/subview.do) at the [Sungshin Women's University](https://www.sungshin.ac.kr/) in Seoul, Korea titled [*Attestation-based verification of SBOM integrity via consumer-side reproducibility*](https://www.sciencedirect.com/science/article/pii/S2405959526001086):
+
+> Software bills of materials (SBOMs) support supply chain transparency, but they do not prove that a delivered SBOM reproducibly corresponds to its software artifact. Existing signing and provenance mechanisms protect integrity and traceability, yet lack consumer-side reproducible verification. We propose an SBOM integrity verification framework combining procedure disclosure, consumer-side reproduction, authority-generated reference evidence, and digest comparison. A trusted authority records a reference digest, and consumers compare it with locally reproduced and delivered SBOM digests. Experiments on 100 real-world container images show detection of artifact tampering, SBOM substitution, distribution modification, and adaptive tampering beyond signature-based approaches
+
+<br>
+<br>
+
+Finally, if you are interested in contributing to the Reproducible Builds project, please visit our [*Contribute*](https://reproducible-builds.org/contribute/) page on our website. However, you can get in touch with us via:
+
+ * IRC: `#reproducible-builds` on `irc.oftc.net`.
+
+ * Mastodon: [@reproducible_builds at fosstodon.org](https://fosstodon.org/@reproducible_builds)
+
+ * Mailing list: [`rb-general at lists.reproducible-builds.org`](https://lists.reproducible-builds.org/listinfo/rb-general)
=====================================
bin/generate-draft.template
=====================================
@@ -64,8 +64,8 @@ In Debian:
#### Upstream patches
The Reproducible Builds project detects, dissects and attempts to fix as many currently-unreproducible packages as possible. We endeavour to send all of our patches upstream where appropriate. This month, we wrote a large number of such patches, including:
-
-{% for x, ys in patches.items()|sort %}* {{ x }}:
+{% for x, ys in patches.items()|sort %}
+* {{ x }}:
{% for y in ys %} * [#{{ y['id'] }}](https://bugs.debian.org/{{ y['id'] }}) filed against [`{{ y['source'] }}`](https://tracker.debian.org/pkg/{{ y['source'] }}).
{% endfor %}{% endfor %}
=====================================
images/reports/2026-06/1-s2.0-S2405959526001086-main.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/1-s2.0-S2405959526001086-main.png differ
=====================================
images/reports/2026-06/2025-nixpkgs-reproducibility-extended.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/2025-nixpkgs-reproducibility-extended.png differ
=====================================
images/reports/2026-06/DSN-HAP26_muto.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/DSN-HAP26_muto.png differ
=====================================
images/reports/2026-06/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/bit-for-bit-building-sovereign-reproducible-container-supply-chain-devguard.png differ
=====================================
images/reports/2026-06/debian-lg.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/debian-lg.png differ
=====================================
images/reports/2026-06/debian.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/debian.png differ
=====================================
images/reports/2026-06/diffoscope.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/diffoscope.png differ
=====================================
images/reports/2026-06/fedora.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/fedora.png differ
=====================================
images/reports/2026-06/opensuse.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/opensuse.png differ
=====================================
images/reports/2026-06/repro-threshold.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/repro-threshold.png differ
=====================================
images/reports/2026-06/reproduce.debian.net.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/reproduce.debian.net.png differ
=====================================
images/reports/2026-06/reproducible-builds.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/reproducible-builds.png differ
=====================================
images/reports/2026-06/website.png
=====================================
Binary files /dev/null and b/images/reports/2026-06/website.png differ
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/e2c9acb56121791babd95f86df39e2d05a4fd172
--
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/e2c9acb56121791babd95f86df39e2d05a4fd172
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-commits/attachments/20260709/637b2285/attachment.htm>
More information about the rb-commits
mailing list