[rb-general] offical Debian docker images reproducible? (Re: Reproducible system images)

Holger Levsen holger at layer-acht.org
Mon Jan 6 14:06:46 UTC 2020

Hi Sylvain, Paul & Tianon,

On Thu, Jan 02, 2020 at 09:36:58AM +0100, Sylvain Beucler wrote:
> On 02/01/2020 00:57, Chris Lamb wrote:
> >> Are you familiar with this project?
> >> https://github.com/debuerreotype/debuerreotype
> > Gosh, its somewhat odd to read your own name in other peoples' README
> > files. Whilst this was based on some work I did on debootstrap in 2015
> > [1] speaking in early 2020 (happy New Year all, by the way) I wonder
> > how much of this can or should be moved into upstream debootstrap
> > itself.

(leaving this context for Paul and Tianon to smile ;)

> It sounds like you are discovering this project, which strikes me as odd
> since it's how official Debian Docker images are built, for at least 2
> years, with reproducibility in mind:
> https://hub.docker.com/_/debian/

oh wow, I wasnt aware neither! Many thanks for pointing this out,

> Maybe there's an opportunity for cooperation?

I'd certainly hope so!

Right now I'm now quite sure, where we (r-b.o) should promote them, eg on
https://reproducible-builds.org/who/#Debian or better create
https://reproducible-builds.org/who/#Docker? Or only on

Then upon reading https://hub.docker.com/_/debian/ I miss:
 - checksums of the images
 - instructions how to recreate those images (eg which SOURCE_DATE_EPOCH
   was used)


       PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20200106/92c15930/attachment.sig>

More information about the rb-general mailing list