Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FEAT] reproducible rebuild #2684

Open
freedom-foundation opened this issue Oct 11, 2024 · 0 comments
Open

[FEAT] reproducible rebuild #2684

freedom-foundation opened this issue Oct 11, 2024 · 0 comments

Comments

@freedom-foundation
Copy link

need reproducible rebuild. A password manager is a security critical app therefore the highest priority of apps to verify reproducable and garuntee veritable to the purported source. In the same way F-Droid claims "It is built and signed by F-Droid, and guaranteed to correspond to this source tarball." you may do the same. Nobody should be using a password manager which they cannot trust.
F-Droid used to be this way where the app devs would sign their own code or apk, however that key system worked.

Expect a checksum similar to what can be seen on verification.f-droid.org

Wheeler's DDC methodology may be used to verify the app is guarunteed to correspond to the sourcecode given. I have a repo to colab on DDC https://github.com/freedom-foundation/Countering_Trusting_Trust_through_Diverse_Double-Compiling

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant