Collaborative Working Sessions - Public verification service

Server collects build data

Use cases

Use data to determine what’s causing builds to differ

What percentage of X builds reproducibly

Building or rebuilding stuff

Components are things like build environment and sources

Build spec

Build spec:

Environment:

Outputs:

(above is the payload)

Metadata:

Formats: - Linked Data / RDF - JSON - SBOM / SPDX / CycloneDX / … ? - Maybe In-TOTO?

Hook In: - After ‘Fetch’ / Before ‘Build’ - After ‘Artifact Generation’

People interested in contributing to implementation: - Hervé Boutemy (hboutemy@apache.org) - Arnout Engelen (arnout@bzzt.net) - Janis Peyer (janispeyer@bluewin.ch) - Nicolas (boklm@torptoject.org) - quae@daurnimator.com