social.tchncs.de is one of the many independent Mastodon servers you can use to participate in the fediverse.
A friendly server from Germany – which tends to attract techy people, but welcomes everybody. This is one of the oldest Mastodon instances.

Administered by:

Server stats:

3.8K
active users

#reproduciblebuilds

3 posts1 participant0 posts today
IzzyOnDroid ✅<p>You're interested in Reproducible Builds for Android apps? We've just updated our Wiki on those:</p><p><a href="https://gitlab.com/IzzyOnDroid/repo/-/wikis/Reproducible-Builds/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gitlab.com/IzzyOnDroid/repo/-/</span><span class="invisible">wikis/Reproducible-Builds/</span></a></p><p>There are new pages for setting up build recipes, and debugging/fixing RBs – which should help you when running your own builder. Which you btw can set up on your Linux machine within 5 minutes using the scripts provided at <a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a> :awesome:</p><p>Developers also find pages there on making/keeping their apps RB.</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Farhan 🥳</p><p><a href="https://apt.izzysoft.de/packages/ly.com.tahaben.farhan" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/ly.co</span><span class="invisible">m.tahaben.farhan</span></a></p><p>Farhan empowers you to take control of your digital experience. Say goodbye to manipulative strategies used by other apps and get ready to focus on what matters to you.</p><p>Thanks to the work of Taha Ben Ashur, its developer, the app is now RB :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, WalkersGuide 🥳</p><p><a href="https://apt.izzysoft.de/packages/org.walkersguide.android" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/org.w</span><span class="invisible">alkersguide.android</span></a></p><p>WalkersGuide is a navigational aid primarily intended for blind and visual impaired pedestrians. It calculates routes and shows nearby points of interest.</p><p>Thanks to the help by its developer, the app is RB now :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Rattlegram 🥳</p><p><a href="https://apt.izzysoft.de/packages/com.aicodix.rattlegram" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.a</span><span class="invisible">icodix.rattlegram</span></a></p><p>Rattlegram lets you transmit short text messages over COFDMTV encoded audio signals.</p><p>Thanks to joined efforts with its developer, Rattlegram (along with its 2 sister-apps) is now RB :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Inure 🥳</p><p><a href="https://github.com/Hamza417/Inure" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/Hamza417/Inure</span><span class="invisible"></span></a></p><p>Inure is a powerful open source applications manager and analyzer with a good-looking &amp; easy to use interface.</p><p>Joint efforts from 3 parties at work here. Most work was done by the developer (thank you, Hamza!) F-Droid devs joined in, and IzzyOnDroid's new builder tools finally brought in the victory on the developer's side. With the next sync, Inure will be available at IoD and F-Droid as RB :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Cheers 🥂</p><p>555 apps (43.1%)</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://kolektiva.social/@licho" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>licho</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@osman" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>osman</span></a></span> provide evidence the code <span class="h-card" translate="no"><a href="https://mastodon.world/@signalapp" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>signalapp</span></a></span> released is actually being deployed.</p><ul><li>Whereas <span class="h-card" translate="no"><a href="https://monocles.social/@monocles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>monocles</span></a></span> has <a href="https://infosec.space/tags/ReproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ReproducibleBuilds</span></a> to the point that <span class="h-card" translate="no"><a href="https://floss.social/@fdroidorg" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fdroidorg</span></a></span> literally pulls their <code>git</code> and builds it from source.</li></ul><p>Not to mention pushing a <a href="https://infosec.space/tags/Shitcoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Shitcoin</span></a>-<a href="https://infosec.space/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a> (<a href="https://infosec.space/tags/MobileCoin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MobileCoin</span></a>) disqualifies <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> per very design!<br><a href="https://www.youtube.com/watch?v=tJoO2uWrX1M" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=tJoO2uWrX1M</span><span class="invisible"></span></a></p><ul><li>Given the collection of <a href="https://infosec.space/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> like <a href="https://infosec.space/tags/PhoneNumbers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumbers</span></a>, the ability to restrict functionality based off those and the fact that <a href="https://infosec.space/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> is subject to <a href="https://infosec.space/tags/CloudAct" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CloudAct</span></a> make it inherently not trustworthy.</li></ul><p>And don't even get me started on the fact.it's not sustainable to run it as a <a href="https://infosec.space/tags/VCmoneyBurningParty" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VCmoneyBurningParty</span></a>!</p><ul><li>As soon as Signal becomes a problem, it will be taken offline, and due to the fact that it is <a href="https://infosec.space/tags/centralized" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>centralized</span></a>, <a href="https://infosec.space/tags/proprietary" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proprietary</span></a>, <a href="https://infosec.space/tags/SingleVendor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleVendor</span></a> &amp; <a href="https://infosec.space/tags/SingleProvider" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SingleProvider</span></a> that's trivial for authorities.</li></ul><p>Same as identifying users: They already got a <a href="https://infosec.space/tags/PhoneNumber" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PhoneNumber</span></a> which in many juristictions one can't even obtain without <a href="https://infosec.space/tags/ID" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ID</span></a> legally, thus making it super easy to i.e. find and locate a user. Even tze cheapest LEAs can force their local M(V)NOs to <a href="https://infosec.space/tags/SS7" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SS7</span></a> a specific number...</p><ul><li>All these are <em>unnecessary risks</em>, that could've been avoided, but explicitly don't even get remediated retroactively!</li></ul><p>Again: Signal has a <a href="https://infosec.space/tags/Honeypot" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Honeypot</span></a> stench, and you better learn proper <a href="https://infosec.space/tags/E2EE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>E2EE</span></a>, <a href="https://infosec.space/tags/SelfCustody" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SelfCustody</span></a> and <a href="https://infosec.space/tags/TechLiteracy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechLiteracy</span></a> because <a href="https://web.archive.org/web/20210606070919/twitter.com/thegrugq/status/1085614812581715968" rel="nofollow noopener noreferrer" target="_blank"><em>corporations can't pull the 5th [Amendment] on your behalf</em>!</a></p>
jbz<p>"Over the last few releases, we changed our build infrastructure to make package builds reproducible. This is enough to reach 90%. The remaining issues need to be fixed in individual packages. After this Change, package builds are expected to be reproducible. Bugs will be filed against packages when an irreproducibility is detected. The goal is to have no fewer than 99% of package builds reproducible."</p><p><a href="https://www.phoronix.com/news/Fedora-43-Expect-Reproducible" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">phoronix.com/news/Fedora-43-Ex</span><span class="invisible">pect-Reproducible</span></a></p><p><a href="https://indieweb.social/tags/fedora" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fedora</span></a> <a href="https://indieweb.social/tags/reproduciblebuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproduciblebuilds</span></a> <a href="https://indieweb.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://indieweb.social/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a></p>
IzzyOnDroid ✅<p>Oh, and the Readme of the rbuilder_setup repo needed a few updates as well 🙈 Done now: <a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a></p><p>If you've set up a builder, we'd love to hear from your experiences – concerning the setup (was it easy enough and straight-forward?) as well as from operation :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a></p>
IzzyOnDroid ✅<p>With our rbuilder_setup scripts now ready, the wiki page on Verification Builders has been updated, too:</p><p><a href="https://gitlab.com/IzzyOnDroid/repo/-/wikis/Reproducible-Builds/Verification-Builder" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gitlab.com/IzzyOnDroid/repo/-/</span><span class="invisible">wikis/Reproducible-Builds/Verification-Builder</span></a></p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Wanted to run your own builder for <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> and were disappointed our RBuilder Setup was only available for Debian-based systems? Then we have good news for you: a few min ago, 2 PRs have been merged. The setup scripts now also support RPM &amp; Arch based systems 🥳</p><p>RPM/Arch lack packages for apksigner &amp; dexdiff (which are needed for debugging). We're on it, those will follow hopefully soon™.</p><p>Thanks to <span class="h-card" translate="no"><a href="https://mastodon.social/@Iamlooker" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Iamlooker</span></a></span> and Patrick (from FlorisBoard) for your help!</p><p><a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a></p>
IzzyOnDroid ✅<p>We just got our first feedback on our RB builder setup scripts (<a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a>) today, and that made us really happy, seeing a goal achieved:</p><p>&gt; I did set up and ran your scripts in my Ubuntu server (noble) and found the process of setting it up a breeze, and it helped me a lot into finding the source of the issue.</p><p>So if you're an Android dev looking into getting your app RB, it might be worth a try!</p><p><a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a></p>
IzzyOnDroid ✅<p>A salute to Douglas Adams: RB coverage at the IzzyOnDroid repo now reached 42% (covering 536 apps) 🥳</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>For our "automated builder setup", I've just prepared a PR adding support for RPM based systems. The PR is still marked WIP as I don't have any RPM test system at hand here – so I'm calling out for help:</p><p>Anybody willing to test the setup scripts on Fedora, RHEL, CentOS or the likes? 🙏 </p><p>(more tests on Debian-based systems (Debian, Ubuntu, Mint …) are of course welcome, too)</p><p><a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup/pulls/4" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup/pulls/4</span></a></p><p>:boost_love:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, Minimo Launcher 🥳</p><p><a href="https://apt.izzysoft.de/packages/com.minimo.launcher" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.m</span><span class="invisible">inimo.launcher</span></a></p><p>Designed for users who want to de-clutter their home screen, Minimo offers a clean and intuitive minimalist interface that prioritizes functionality without unnecessary distractions.</p><p>And thanks to the efforts by its developer, its new release today is RB :awesome:</p><p>RB status at IoD now: 530 apps (41.7%)</p><p><a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a></p>
IzzyOnDroid ✅<p>Welcome to the RB family, RadioUpnp 🥳</p><p><a href="https://apt.izzysoft.de/packages/com.watea.radio_upnp" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apt.izzysoft.de/packages/com.w</span><span class="invisible">atea.radio_upnp</span></a></p><p>RadioUpnp reads any internet radio. Minimalist and full customizable. With support for UPnP/DLNA. And thanks to the efforts by its developer, with its latest release today it is reproducible :awesome:</p><p>So the current RB status at the IzzyOnDroid repo is: 508 apps (40.6%)</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>New day, new Milestone: now 500 apps at <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> are <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> :awesome:</p>
IzzyOnDroid ✅<p>🐣 oops… the Easter egg hatched early! We've just reached a goal we hoped to achieve around Easter:</p><p>At <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> 40% – so 2 out of every 5 apps – are now <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> 🥳</p><p>So whenever you see one or more green shields next to the version of an app in our repo browser at <a href="https://apt.izzysoft.de/fdroid" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">apt.izzysoft.de/fdroid</span><span class="invisible"></span></a> you can be sure: this was built exactly from the source code it claims to be, nothing added or taken away.</p><p>Oh, and we should roll out those new shields soon™, so you see the independent builders 😉</p>
IzzyOnDroid ✅<p><a href="https://floss.social/tags/AndroidAppRain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AndroidAppRain</span></a> at <a href="https://apt.izzysoft.de/fdroid" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">apt.izzysoft.de/fdroid</span><span class="invisible"></span></a> today just brings you 6 updated apps – but all of them are RB. Second time now that we can announce an "RB only" update :awesome:</p><p><a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a></p>
IzzyOnDroid ✅<p>Want to try running your own builder – to confirm apps as <a href="https://floss.social/tags/reproducibleBuilds" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>reproducibleBuilds</span></a> or just to build your own apps? At <a href="https://floss.social/tags/IzzyOnDroid" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IzzyOnDroid</span></a> we've just made "easy setup scripts" available which should take care for all requirements, while letting you choose which parts you want:</p><p><a href="https://codeberg.org/IzzyOnDroid/rbuilder_setup" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/IzzyOnDroid/rbuil</span><span class="invisible">der_setup</span></a></p><p>These scripts are not yet thoroughly tested (just a bit on Linux Mint/Debian/Ubuntu), so we'd welcome volunteers &amp; their feedback.</p><p>Thanks to <span class="h-card" translate="no"><a href="https://social.nlnet.nl/@nlnet" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nlnet</span></a></span> for supporting us on this project! You're awesome :awesome:</p>