Java Reproducible builds

Martín Coll <mc-/[email protected]>
Newsgroups gmane.comp.encryption.bouncy-castle.devel
Message-ID <CA+fZ1CeVaB8Yn2Zq9gnftup9rCi0pNhvGB8RYFvJa0ZCbJZbJQ@mail.gmail.com>
As part of our work at RSK <https://rsk.co/> to strengthen our
infrastructure, we started an effort to publish reproducible builds of our
dependencies. Since we’re in the process of upgrading BouncyCastle, we
decided to start with this library:
https://github.com/rsksmart/reproducible-builds/tree/master/bouncycastle/1.59
.

In that repository, we published a Dockerfile with the recipe to build
BouncyCastle 1.59 in a reproducible way: the same JAR, bit by bit, can be
verified independently from these open sources.

We also decided to expose and compile the lightweight API JAR file
<https://github.com/rsksmart/reproducible-builds/blob/master/bouncycastle/1.59/0001-Add-lcrypto-as-an-output-JAR.patch>,
since we are not signing the JAR and can’t take advantage of the JCE
provider.

Our end goal is to collaborate to support reproducible builds upstream, so
let us know if you are interested in integrating this into your release
process.

Best,
Martín Coll.
​
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.