Collaborative Working Sessions - Distributed verification III

Evaluation criteria

Must Have

Builds must be discoverable along with useful metadata

Must scale

Must be be resilient against

Must be possible to delegate trust to another party or parties in a limited controlled matter

A rebuilder should be able to indicate what they built in a non-repudiatable way

We need to be able to identify a rebuilder securely such as with a public key

UX is essential especially for non-interested users

Extra nice to have

Doing a rebuild should be accessible

There should not be properties that discourage institutional diversity in rebuilders.

Developer experience is important and developers shouldn’t be expected care for RB.

Nice to have

Diverse rebuilder support is desirable

Ideally there is a usable means to report irreproducibility possibly implicitly

Ideally closed source / secrets in software should be supported

Optional

Support for diverse build inputs would be desirable

Ideally there is a way to verify a rebuilder did work