Help the Reproducible Builds effort!

The not-for-profit Reproducible Builds effort needs your help to continue its work towards ensuring the security of computer systems of all shapes and sizes around the world. We use any and all donated funds to ensure focused and intense work on ensuring this mission.

Software Freedom Conservancy

The Reproducible Builds project is a member of the Software Freedom Conservancy, a 501(c)3 non-profit organisation. Conservancy has allowed us to pool organisational resources with other projects, such as Selenium, Inkscape, Samba, and Wine, in order to reduce the management overhead associated with creating our own, dedicated legal entity.

See who is currently supporting the Reproducible Builds project.

About the project

Whilst anyone may inspect the source code of free and open source software for malicious flaws, most software is distributed pre-compiled to end users.

The motivation behind the Reproducible Builds project is to permit verification that no flaws have been introduced during the compilation process—either maliciously or accidentally—by promising identical results are always generated from a given source, thus allowing multiple third-parties to come to a consensus on whether a system is compromised.

Your continued support will be key in solving this important problem which affects systems of all sizes, from embedded microcontrollers to the largest government and corporate systems.

Past work

Future work

The Reproducible Builds team has demonstrated that it is, in principle, possible to build a Linux distribution in a reproducible manner and have solved many of the issues in doing so.

However, the next release of Debian is currently not yet 100% reproducible and funding to support on-going maintenance of critical infrastructure will be absolutely essential to reach this goal.

This not only includes the administration of around 42 build nodes across multiple architectures, it requires continuous and patient work with package maintainers and upstreams to merge reproducibility-related patches. It also includes extending the scope of our testing framework to even more projects, as well as improving the existing tests and reports.

In addition, there are currently no tools that let a user know whether packages that they are installing are reproducible or not, required to “close the loop” and allow end-users to finally truly validate the software they are running on their machines.

Furthermore, maintaining momentum — both in terms of public perception and in private — around the various related projects such as diffoscope, etc. will be key in ensuring reproducible builds become a reality.

Benefits of sponsorship

Please see our list of current sponsors.

Logos

Levels

Below are the names and amounts associated with levels of sponsorship (all values in USD and per year):

Non-monetary Donations

The Reproducible Builds project will naturally consider non-monetary donations to the project such as hardware or hosting where we will set a sponsorship level appropriately. (Please note that non-monetary donations may not be tax-deductible; to confirm, you should seek the advice of a qualified tax professional. In general, we suggest cash donations, as that process is much simpler.)

Contact

Please contact us (info@reproducible-builds.org) for more information. Thank you for your consideration and we thank you in advance for your support.

Paypal

The easiest way to individually donate to the project is through PayPal. You can use this button to donate to us:

Other methods

We can accept check donations drawn in USD from banks in the USA. Donations from banks outside of the US or not in USD should be handled by wire transfer. Please make your check payable to “Software Freedom Conservancy, Inc.” and to place “Directed donation: Reproducible Builds” in the memo field. Checks should then be mailed to:

Software Freedom Conservancy, Inc.
137 Montague ST STE 380
BROOKLYN, NY 11201
USA

Conservancy also accepts other methods to receive donations, including US cheques and wire transfers. If you are interested please get in touch with us!