View Issue Details

IDProjectCategoryView StatusLast Update
0004141SOGoPackaging (Debian)public2017-04-09 19:53
Reporterskrupellos Assigned To 
PrioritynormalSeverityfeatureReproducibilityalways
Status newResolutionopen 
Product Version3.2.8 
Summary0004141: Reproducible Builds
Description

Currently each build produces a different output, even though the source files haven't changed. Debian (hence the category) and other distributions try to avoid this and make reproducible builds (for the reasons and more infos see: https://reproducible-builds.org/).

One step into this direction is to remove the build date from the generated output.

Debian has a corresponding patch https://anonscm.debian.org/git/collab-maint/sogo.git/tree/debian/patches/0005-Remove-build-date.patch

Personally, I would also remove the exact version number from places, publicly accessible. So an attacker has to use at least fingerprinting to get possible attack vectors. Hence I also removed the version number in my patch: https://github.com/Skrupellos/sogo-patches/blob/v3.2.8/01-reproduceable_build.patch

TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2017-04-09 19:52 skrupellos New Issue