Group: Software/FSDG distributions/Security
(→Releases and signatures: Add Ututo S) |
(→Releases and signatures: Add ProteanOS) |
||
Line 8: | Line 8: | ||
! Distribution | ! Distribution | ||
! Signed installers | ! Signed installers | ||
+ | ! Signed development source code | ||
|- | |- | ||
! Dragora 3.0-beta1 | ! Dragora 3.0-beta1 | ||
Line 31: | Line 32: | ||
|- | |- | ||
! ProteanOS | ! ProteanOS | ||
− | | | + | | {{yes|Yes: signed ProteanOS Development Kit commits}}<ref>http://proteanos.com/doc/install/prokit/</ref> |
|- | |- | ||
! PureOS 10 (byzantium) | ! PureOS 10 (byzantium) |
Revision as of 11:23, 22 February 2023
Contents
Introduction
This page tracks the progress of FSDG distributions with regard to reproducible builds, bootstrapable builds and other similar security features.
Releases and signatures
Distribution | Signed installers | Signed development source code |
---|---|---|
Dragora 3.0-beta1 | Checksums only[1] | |
Dynebolic 3.0-beta | Broken: signed broken checksums (md5)[2] | |
Guix 1.4.0 | Yes, signed images[3] | |
Guix "latest" | No[4] | |
Hyperbola v0.4.2 | Yes, signed images[5] | |
LibreCMC | Yes, signed checksums[6] | |
Parabola | Yes[7] | |
ProteanOS | Yes: signed ProteanOS Development Kit commits[8] | |
PureOS 10 (byzantium) | Checksums only.[9] | |
Replicant 6.0 0004 | Yes, signed images[10] | |
Trisquel 10.0.1 | Yes, signed images[11] | |
Ututo S | No: broken checksums (md5) only[12] |
Repdoducible builds and bootstrapable builds
Self hosted distributions
Distribution | Reproducible builds officially supported[13] | Comments |
---|---|---|
Dragora | ? |
|
Dynebolic | ? |
|
Guix | Yes |
|
Hyperbola | ? |
|
Parabola | ? |
|
PureOS | ? |
|
Trisquel | ? |
|
Ututo S | ? |
|
Small distributions
Distribution | Reproducible builds officially supported[13] | Comments |
---|---|---|
LibreCMC | ? |
|
ProteanOS | ? |
|
Replicant | not yet |
|
- ↑ https://mirror.fsf.org/dragora/v3/iso/beta1/
- ↑ https://files.dyne.org/dynebolic/
- ↑ https://guix.gnu.org/en/download/
- ↑ https://guix.gnu.org/en/download/latest/
- ↑ https://wiki.hyperbola.info/doku.php?id=en:manual:verify_live_images
- ↑ signed checksums: https://librecmc.org/librecmc/downloads/snapshots/v1.5.12/targets/ath79/generic/
- ↑ https://wiki.parabola.nu/Get_Parabola
- ↑ http://proteanos.com/doc/install/prokit/
- ↑ https://downloads.puri.sm/byzantium/gnome/2022-06-02/
- ↑ https://ftp.osuosl.org/pub/replicant/images/replicant-6.0/0004/images/
- ↑ https://cdimage.trisquel.info/trisquel-images/
- ↑ http://www.ututo.org/downloads/
- ↑ 13.013.1 If reproducible builds officially supported, we should be able to open bugs about non reproducible packages and/or send patches to fix them. If it is not supported we could try to send patches to enable reproducible builds and/or help the distribution supporting it instead.
- ↑ 14.0014.0114.0214.0314.0414.0514.0614.0714.0814.0914.10 The official lists of projects supporting reproducible is at https://reproducible-builds.org/projects/ . Note that not all theses projects are FSDG compliant and that some might even contain nonfree software and other really problematic issues.
- ↑ https://wiki.parabola.nu/Reproducible_Builds