buildinfo question

Vagrant Cascadian vagrant at reproducible-builds.org
Tue Dec 13 18:14:55 UTC 2022


On 2022-12-13, James Addison via rb-general wrote:
> As Debian's buildinfo[1] wiki page hints, it's difficult to determine
> whether a build dependency is genuinely required at build-time,
> compared to: it was required in the past, but has become dependency
> cruft.
>
> I was wondering: are there reproducible-builds efforts underway (in
> Debian or other ecosystems) to determine the packages that were
> involved (first-pass approximation: at least one file belonging to the
> package was read from the filesystem by a child of the build process
> -- anything else?) during a reproducible package build?

I have certainly used an ad-hoc simpler but related technique, building
with and without a build-dependency, and checking for bit-for-bit
identical results.

It would be interesting to do something more systematic like your
suggestion, though I'm not aware of anything at the moment.

live well,
  vagrant
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20221213/10801b2b/attachment.sig>


More information about the rb-general mailing list