On Wed, Feb 01, 2023 at 12:53:24PM -0500, David A. Wheeler wrote:
> I recommend that the reproducible-builds website have a short article
> *specifically* recommending how signatures, OmniBOR data, & similar metadata should be shared.
> Is there agreement on adding such a page?

Yes, I'd say so. I'm not sooo sure about agreement for what exactly should be on that
page ;) So, yes, please, patches welcome, also incrementially!

> At least one person I've talked to claims that reproducible builds are a security vulnerability,
> because he assumes that signatures must be embedded within executables.
> That's wrong, but making it clear to others why it's wrong would be helpful.


