View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0004141 | SOGo | Packaging (Debian) | public | 2017-04-09 19:52 | 2017-04-09 19:53 |
Reporter | skrupellos | Assigned To | |||
Priority | normal | Severity | feature | Reproducibility | always |
Status | new | Resolution | open | ||
Product Version | 3.2.8 | ||||
Summary | 0004141: Reproducible Builds | ||||
Description | Currently each build produces a different output, even though the source files haven't changed. Debian (hence the category) and other distributions try to avoid this and make reproducible builds (for the reasons and more infos see: https://reproducible-builds.org/). One step into this direction is to remove the build date from the generated output. Debian has a corresponding patch https://anonscm.debian.org/git/collab-maint/sogo.git/tree/debian/patches/0005-Remove-build-date.patch Personally, I would also remove the exact version number from places, publicly accessible. So an attacker has to use at least fingerprinting to get possible attack vectors. Hence I also removed the version number in my patch: https://github.com/Skrupellos/sogo-patches/blob/v3.2.8/01-reproduceable_build.patch | ||||
Tags | No tags attached. | ||||
Date Modified | Username | Field | Change |
---|---|---|---|
2017-04-09 19:52 | skrupellos | New Issue |