# reproducible builds

A software build practice that enables verification by reproducing byte-for-byte identical binary packages from a given source.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Supporter spotlight: Jochen Sprickerhof on reproducible builds

DevFeed: [Supporter spotlight: Jochen Sprickerhof on reproducible builds](<https://devfeed.tech/articles/supporter-spotlight-jochen-sprickerhof-on-reproducible-builds-34163.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2026/09/15/supporter-spotlight-jochen-sprickerhof/>)

Published: 2026-09-15T03:54:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [F-Droid](<https://devfeed.tech/topics/f-droid.md>), [Robotics](<https://devfeed.tech/topics/robotics.md>), [Point cloud](<https://devfeed.tech/topics/point-cloud.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [org](<https://devfeed.tech/tags/org.md>), [programming](<https://devfeed.tech/tags/programming.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [robotics](<https://devfeed.tech/tags/robotics.md>)

### AI overview

An interview with Jochen Sprickerhof, a freelance programmer and Reproducible Builds core team member, covering his work on Debian, F-Droid, software projects, and bit-for-bit reproduction of Debian packages.

### Source excerpt

The Reproducible Builds project relies on several projects, supporters and sponsors for financial support, but they are also valued as ambassadors who spread the word about our project and the work that we do. This is the ninth installment in a series featuring the projects, companies and individuals who support the Reproducible Builds project. We started this series by featuring the Civil Infrastructure Platform project, and followed this up with a post about the Ford Foundation as well as recent ones about ARDC, the Google Open Source Security Team (GOSST), Bootstrappable Builds, the F-Droid project, David A. Wheeler, Simon Butler and Kees Cook. Today, however, we will be talking with Jochen Sprickerhof, one of the newer members of the Reproducible Builds project core team. Vagrant Cascadian: Could you tell me a bit about yourself? What sort of things do you work on? Jochen Sprickerhof: I am a freelance programmer working on Open Source. Mainly doing Debian, F-Droid and some smaller software projects. In general I made it a habit to look into every software I use and try to fix bugs or add features I need. In Debian, I maintain about 180 packages with topics covering home banking, build systems and robotics. Most of my time, I currently work on reproduce.debian.net, where we try to bit-for-bit reproduce the packages distributed by Debian. Vagrant: Could you describe the path that lead you to working on reproducible builds? Jochen: I started my Debian journey as a teenager, converting my school to Debian and serving as its system administrator for 13 years. After studying Applied System Science, I joined the university's robotics labs, where I worked on the Robot Operating System (ROS) and the Point Cloud Library (PCL). In the end, I enjoyed programming more than writing papers, so I eventually left academia for a robotics startup. Some years ago, I realized that the open source work I was doing in my spare time was actually the work I cared most about. Nowadays I

## Reproducible Builds summit 2026 to take place in Gothenburg

DevFeed: [Reproducible Builds summit 2026 to take place in Gothenburg](<https://devfeed.tech/articles/reproducible-builds-summit-2026-to-take-place-in-gothenburg-34162.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2026/08/12/reproducible-builds-summit-in-gothenburg/>)

Published: 2026-08-12T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [builds](<https://devfeed.tech/topics/builds.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [inclusive](<https://devfeed.tech/tags/inclusive.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [summit](<https://devfeed.tech/tags/summit.md>), [tools](<https://devfeed.tech/tags/tools.md>), [users](<https://devfeed.tech/tags/users.md>)

### AI overview

The Reproducible Builds summit will take place in Gothenburg, Sweden, from September 22 to 24, 2026. The event will bring together participants to discuss project status, collaboration, broader adoption, and technical solutions.

### Source excerpt

This event is happening soon -- see below for registration instructions! We are extremely pleased to announce the upcoming Reproducible Builds summit, which will take place from September 22nd--24th 2026 in the city of Gothenburg, Sweden. This year, we are thrilled to host the tenth edition of this exciting event, following the success of previous summits in various iconic locations around the world, including Vienna (2025), Hamburg (2023--2024), Venice (2022), Marrakesh (2019), Paris (2018), Berlin (2017), Berlin (2016) and Athens (2015). If you're excited about joining us this year, please make sure to read the event page which has more details about the event and location. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However, even if you do not receive a personal invitation, please do email the organizers and we will find a way to accommodate you. About the event The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving. Schedule Although the exact content of the meeting will be shaped by the participants, the main goals will include: Update & exchange about the status of reproducible builds in various projects. Improve collaboration both between and inside projects. Expand the scope and reach of reproducible builds to more projects. Work together and hack on solutions. Establish space for more strategic and long-term thinking than is possible in virtual channels. Brainstorm designs on tools enabling users to get the most benefits from reproducible builds. Discuss how reproducible builds w

## Fighting Hyrum's Law in LLVM

DevFeed: [Fighting Hyrum's Law in LLVM](<https://devfeed.tech/articles/fighting-hyrum-s-law-in-llvm-31128.md>)

Original publisher: [Read original article](<https://maskray.me/blog/fighting-hyrums-law-in-llvm>)

Published: 2026-05-10T07:00:00Z

Content type: article

Language: en

Sources: [MaskRay](<https://devfeed.tech/sources/maskray.md>)

Topics: [LLVM](<https://devfeed.tech/topics/llvm.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [hash](<https://devfeed.tech/topics/hash.md>)

Tags: [clang](<https://devfeed.tech/tags/clang.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [hash](<https://devfeed.tech/tags/hash.md>), [lld](<https://devfeed.tech/tags/lld.md>), [llvm](<https://devfeed.tech/tags/llvm.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [test](<https://devfeed.tech/tags/test.md>)

### AI overview

This article examines how LLVM can develop dependencies on unspecified or incidental behavior under Hyrum's Law, causing output variation that harms reproducible builds, bisection, and bug reports. It describes hash-seed perturbation, reverse container iteration, and iterator invalidation checks as mechanisms for exposing such dependencies.

### Source excerpt

With a sufficient number of users of an API, it does not matter what you promise in the contract: all observable behaviors of your system will be depended on by somebody. -- Hyrum's Law In a compiler, the most common form of Hyrum's Law is dependence on unspecified behavior -- hash bucket order, the order of equal elements after std::sort, padding offsets. The same framing covers a few cases that are technically undefined behavior (use of an invalidated iterator) or plain incidental properties (ABI struct layout, ELF section offsets). When the compiler itself harbors such a dependency, the symptom is usually output that varies build-to-build: an unstable sort that lands differently after the standard library changes, a hash map whose iteration order shifts when the hash function does. Occasionally the variation is run-to-run within a single build -- DenseMap<void *, X> keys with an ASLR-derived seed reorder buckets each invocation. Either way, reproducible builds, bisection, and bug reports all assume same input -> same output, and a stealth Hyrum dependency breaks that. This post surveys some mechanisms that perturb the contract's blind spots so dependencies cannot quietly form.

## Reviving a Static Blog with Nix and Reproducible Builds

DevFeed: [Reviving a Static Blog with Nix and Reproducible Builds](<https://devfeed.tech/articles/reviving-the-blog-21147.md>)

Original publisher: [Read original article](<https://ocramius.github.io/blog/reviving-the-blog/>)

Published: 2026-02-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Marco Pivetta](<https://devfeed.tech/sources/marco-pivetta.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [PHP](<https://devfeed.tech/topics/php.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [WordPress](<https://devfeed.tech/topics/wordpress.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github](<https://devfeed.tech/tags/github.md>), [php](<https://devfeed.tech/tags/php.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>)

### AI overview

The author returns to blogging and explains how they stabilized a Sculpin-based static website by using Nix Flakes to pin dependencies and support reproducible builds. The article also covers Composer dependency hashing and deployment to GitHub Pages.

### Source excerpt

I'm back! The last time I blogged was in 2017: a lot has changed since then, and after a decade of ignoring blogging, I will attempt to put some regularity into it again. The times call for it: having a personal space that is really "our own" is extremely important, and it is as important as having something to read that is written by other humans, and not slop. I mainly stopped blogging for two reasons: Wordpress and similar tools are terrible, for rarely changing content. I'd rather not blog, than host a dynamic website just for serving static webpages My static site generation pipeline heavily relied on my workstation's software dependencies, which shifted continuously, breaking the website build at all times. Stabilizing the build Note: This section describes the Nixification of the blog, done in this pull request. You can skip this, if you prefer reading the PR instead. The first thing to do is to get everything under control again. Since a few years back, I started heavily relying on Nix, a lazy functional language that is perfect to achieve reproducible builds and environments. At the time of this writing, this website is built via Sculpin, a static website generator whose dependency upgrades I've neglected for far too long. In order to "freeze" the build in time, I used a Nix Flake to pin all the dependencies down, preventing any further shifts in dependency versions: { inputs = { nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable"; flake-utils.url = "github:numtide/flake-utils"; }; outputs = { self, nixpkgs, flake-utils, composer2nix, ... }@inputs: flake-utils.lib.eachDefaultSystem ( system: { packages = { # things that will stay extremely stable will go here }; } ); } The above will "pin" dependencies such as composer or php, preventing them from drifting apart, unless a commit moves them. This is also thanks to the built-in flake.lock mechanism of Nix Flakes. Because Composer does not compute content hashes of PHP dependencies, NixOS cannot directly u

## Strengthening your Software Supply Chain

DevFeed: [Strengthening your Software Supply Chain](<https://devfeed.tech/articles/strengthening-your-software-supply-chain-23031.md>)

Original publisher: [Read original article](<https://www.javaadvent.com/2025/12/strengthening-your-software-supply-chain.html>)

Author: Andres Almiray

Published: 2025-12-12T03:03:02Z

Content type: article

Language: en

Sources: [Java Advent Calendar](<https://devfeed.tech/sources/java-advent-calendar.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [Java](<https://devfeed.tech/topics/java.md>), [Software](<https://devfeed.tech/topics/software.md>), [Maven](<https://devfeed.tech/topics/maven.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [build-tools](<https://devfeed.tech/tags/build-tools.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [devops](<https://devfeed.tech/tags/devops.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [java](<https://devfeed.tech/tags/java.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article explains how to strengthen the Java software supply chain beyond relying on build tools alone. It discusses SLSA security controls, attacks such as Log4Shell and the XZ backdoor, reproducible artifacts, and support from JReleaser for applying these practices.

### Source excerpt

According to Wikipedia, a software supply chain is the components, libraries, tools, and processes used to develop, build, and publish a software artifact. The Java space provides thousands upon thousands of libraries that may be consumed as dependencies for building projects. Many of these libraries rely on Apache Maven as their build tool of choice, [...] The post Strengthening your Software Supply Chain appeared first on JVM Advent.

## Inside Go -- How It Really Works: Series Kickoff

DevFeed: [Inside Go -- How It Really Works: Series Kickoff](<https://devfeed.tech/articles/inside-go-how-it-really-works-series-kickoff-39762.md>)

Original publisher: [Read original article](<https://furkankolcu.com/post/inside-go-how-it-really-works-series-kickoff>)

Author: Furkan Kolcu

Published: 2025-09-11T10:16:52Z

Content type: article

Language: en

Sources: [Furkan Kolcu - Software Engineer Blog](<https://devfeed.tech/sources/furkan-kolcu-software-engineer-blog.md>)

Topics: [Go Language](<https://devfeed.tech/topics/go-language.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [Concurrency](<https://devfeed.tech/topics/concurrency.md>), [Code](<https://devfeed.tech/topics/code.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>), [escape analysis](<https://devfeed.tech/topics/escape-analysis.md>), [generics](<https://devfeed.tech/topics/generics.md>), [modules](<https://devfeed.tech/topics/modules.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>)

Tags: [compilation](<https://devfeed.tech/tags/compilation.md>), [concurrency](<https://devfeed.tech/tags/concurrency.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [generics](<https://devfeed.tech/tags/generics.md>), [go](<https://devfeed.tech/tags/go.md>), [go-compiler](<https://devfeed.tech/tags/go-compiler.md>), [go-concurrency](<https://devfeed.tech/tags/go-concurrency.md>), [go-performance](<https://devfeed.tech/tags/go-performance.md>), [go-runtime](<https://devfeed.tech/tags/go-runtime.md>), [golang](<https://devfeed.tech/tags/golang.md>), [how-go-works](<https://devfeed.tech/tags/how-go-works.md>), [inside-go](<https://devfeed.tech/tags/inside-go.md>), [internals](<https://devfeed.tech/tags/internals.md>), [memory-management](<https://devfeed.tech/tags/memory-management.md>), [performance](<https://devfeed.tech/tags/performance.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This article launches a technical series about how Go works internally. The planned installments cover compilation, memory management, garbage collection, concurrency, the runtime, performance tuning, interfaces, generics, modules, and reproducible builds, with code examples and runtime experiments.

### Source excerpt

A deep-dive series into Go's internals. From compilation to memory management, concurrency, and performance tuning, each part unpacks how Go operates under the hood with clear explanations and real-life code examples.

## Reproducible Builds summit 2025 to take place in Vienna

DevFeed: [Reproducible Builds summit 2025 to take place in Vienna](<https://devfeed.tech/articles/reproducible-builds-summit-2025-to-take-place-in-vienna-34161.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2025/08/20/reproducible-builds-summit-in-vienna/>)

Published: 2025-08-20T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [builds](<https://devfeed.tech/topics/builds.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [announce](<https://devfeed.tech/tags/announce.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [event](<https://devfeed.tech/tags/event.md>), [org](<https://devfeed.tech/tags/org.md>), [summit](<https://devfeed.tech/tags/summit.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

The Reproducible Builds summit is scheduled for October 28-30, 2025, in Vienna, Austria. The eighth summit will bring participants together to discuss project status, collaboration, tools, and the future of reproducible builds.

### Source excerpt

We are extremely pleased to announce the upcoming Reproducible Builds summit, which will take place from October 28th--30th 2025 in the historic city of Vienna, Austria. This year, we are thrilled to host the eighth edition of this exciting event, following the success of previous summits in various iconic locations around the world, including Hamburg (2023--2024), Venice (2022), Marrakesh (2019), Paris (2018), Berlin (2017), Berlin (2016) and Athens (2015). If you're excited about joining us this year, please make sure to read the event page which has more details about the event and location. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However, even if you do not receive a personal invitation, please do email the organizers and we will find a way to accommodate you. About the event The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving. With your help, we will bring this (and several other areas) into life: The main seminar room. Schedule Although the exact content of the meeting will be shaped by the participants, the main goals will include: Update & exchange about the status of reproducible builds in various projects. Improve collaboration both between and inside projects. Expand the scope and reach of reproducible builds to more projects. Work together and hack on solutions. Establish space for more strategic and long-term thinking than is possible in virtual channels. Brainstorm designs on tools enabling users to get the most benefits from reproducible builds. Discuss how reproduc

## Reproducible Builds mourns the passing of Lunar

DevFeed: [Reproducible Builds mourns the passing of Lunar](<https://devfeed.tech/articles/reproducible-builds-mourns-the-passing-of-lunar-34160.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2024/11/14/reproducible-builds-mourns-the-passing-of-lunar/>)

Published: 2024-11-14T15:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [free software](<https://devfeed.tech/topics/free-software.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [org](<https://devfeed.tech/tags/org.md>), [reports](<https://devfeed.tech/tags/reports.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>)

### AI overview

The Reproducible Builds community announces the death of founding member Jérémy Bobbio, known as Lunar, and reflects on his contributions to Reproducible Builds, Debian, Tor, and free software security.

### Source excerpt

The Reproducible Builds community sadly announces it has lost its founding member. Jérémy Bobbio aka 'Lunar' passed away on Friday November 8th in palliative care in Rennes, France. Lunar was instrumental in starting the Reproducible Builds project in 2013 as a loose initiative within the Debian project. Many of our earliest status reports were written by him and many of our key tools in use today are based on his design. Lunar was a resolute opponent of surveillance and censorship, and he possessed an unwavering energy that fueled his work on Reproducible Builds and Tor. Without Lunar's far-sightedness, drive and commitment to enabling teams around him, Reproducible Builds and free software security would not be in the position it is in today. His contributions will not be forgotten, and his high standards and drive will continue to serve as an inspiration to us as well as for the other high-impact projects he was involved in. Lunar's creativity, insight and kindness were often noted. He will be greatly missed. Other tributes: Anargeek.net [FR] LWN Debian Stefano Zacchiroli Linuxfr.org [FR] Software Heritage A history of the Reproducible Builds project

## Reproducible Builds at FOSDEM 2024

DevFeed: [Reproducible Builds at FOSDEM 2024](<https://devfeed.tech/articles/reproducible-builds-at-fosdem-2024-34158.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2024/02/08/reproducible-builds-at-fosdem-2024/>)

Published: 2024-02-08T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [FOSDEM](<https://devfeed.tech/topics/fosdem.md>), [Arch Linux](<https://devfeed.tech/topics/archlinux.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Fedora](<https://devfeed.tech/topics/fedora.md>), [coreboot](<https://devfeed.tech/topics/coreboot.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [coreboot](<https://devfeed.tech/tags/coreboot.md>), [debian](<https://devfeed.tech/tags/debian.md>), [fedora](<https://devfeed.tech/tags/fedora.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>)

### AI overview

The article reports on Reproducible Builds activities at FOSDEM 2024. It highlights Holger Levsen's talk covering the project's history, current state, and future goals, along with other talks on reproducibility, confidential computing, RISC-V bootstrapping, reproducible development environments, HPC experiments, configuration options, and software bills of materials.

### Source excerpt

Core Reproducible Builds developer Holger Levsen presented at the main track at FOSDEM on Saturday 3rd February this year in Brussels, Belgium. Titled Reproducible Builds: The First Ten Years... In this talk Holger 'h01ger' Levsen will give an overview about Reproducible Builds: How it started with a small BoF at DebConf13 (and before), then grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an Executive Order of the President of the United States. And of course, the talk will not end there, but rather outline where we are today and where we still need to be going, until Debian stable (and other distros!) will be 100% reproducible, verified by many. h01ger has been involved in reproducible builds since 2014 and so far has set up automated reproducibility testing for Debian, Fedora, Arch Linux, FreeBSD, NetBSD and coreboot. More information can be found on FOSDEM's own page for the talk, including a video recording and slides. Separate from Holger's talk, however, there were a number of other talks about reproducible builds at FOSDEM this year: Reproducible builds for confidential computing: Why remote attestation is worthless without it by Malte Poll and Paul Meyer. RISC-V Bootstrapping in Guix and Live-Bootstrap by Ekaitz. rix: an R package for reproducible dev environments with Nix by Bruno Rodrigues. Making reproducible and publishable large-scale HPC experiments by Philippe Swartvagher. Documenting and Fixing Non-Reproducible Builds due to Configuration Options by RANDRIANAINA Georges Aaron. ... and there was even an entire track on Software Bill of Materials.

## Farewell from the Reproducible Builds Summit 2023!

DevFeed: [Farewell from the Reproducible Builds Summit 2023!](<https://devfeed.tech/articles/farewell-from-the-reproducible-builds-summit-2023-34157.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2023/11/02/farewell-from-the-reproducible-builds-summit-2023/>)

Published: 2023-11-02T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [reproducibility](<https://devfeed.tech/topics/reproducibility.md>), [builds](<https://devfeed.tech/topics/builds.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>)

Tags: [adb](<https://devfeed.tech/tags/adb.md>), [apache](<https://devfeed.tech/tags/apache.md>), [buildroot](<https://devfeed.tech/tags/buildroot.md>), [builds](<https://devfeed.tech/tags/builds.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [debian](<https://devfeed.tech/tags/debian.md>), [dockerignore-usage](<https://devfeed.tech/tags/dockerignore-usage.md>), [fedora](<https://devfeed.tech/tags/fedora.md>), [germany](<https://devfeed.tech/tags/germany.md>), [github](<https://devfeed.tech/tags/github.md>), [linux](<https://devfeed.tech/tags/linux.md>), [maven](<https://devfeed.tech/tags/maven.md>), [openwrt](<https://devfeed.tech/tags/openwrt.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [security](<https://devfeed.tech/tags/security.md>), [summit](<https://devfeed.tech/tags/summit.md>), [systemd](<https://devfeed.tech/tags/systemd.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

A recap of the seventh Reproducible Builds summit in Hamburg, Germany, covering project updates, reproducibility practices, verification services, filesystem images and containers, package reproducibility, SBOMs, and related discussions.

### Source excerpt

Farewell from the Reproducible Builds summit, which just took place in Hamburg, Germany: This year, we were thrilled to host the seventh edition of this exciting event. Topics covered this year included: Project updates from openSUSE, Fedora, Debian, ElectroBSD, Reproducible Central and NixOS Mapping the "big picture" Towards a snapshot service Understanding user-facing needs and personas Language-specific package managers Defining our definitions Creating a "Ten Commandments" of reproducibility Embedded systems Next steps in GNU Guix' reproducibility Signature storage and sharing Public verification services Verification use cases Web site audiences Enabling new projects to be "born reproducible" Collecting reproducibility success stories Reproducibility's relationship to SBOMs SBOMs for RPM-based distributions Filtering diffoscope output Reproducibility of filesystem images, filesystems and containers Using verification data A deep-dive on Fedora and Arch Linux package reproducibility Debian rebuild archive service discussion ... as well as countless informal discussions and hacking sessions into the night. Projects represented at the venue included: Debian, openSUSE, QubesOS, GNU Guix, Arch Linux, phosh, Mobian, PureOS, JustBuild, LibreOffice, Warpforge, OpenWrt, F-Droid, NixOS, ElectroBSD, Apache Security, Buildroot, Systemd, Apache Maven, Fedora, Privoxy, CHAINS (KTH Royal Institute of Technology), coreboot, GitHub, Tor Project, Ubuntu, rebuilderd, repro-env, spytrap-adb, arch-repro-status, etc. A huge thanks to our sponsors and partners for making the event possible: Event facilitation Platinum sponsor If you weren't able to make it this year, don't worry; just look out for an announcement in 2024 for the next event.

## Blog: How we Sign and Verify Falco Plugins and Rules

DevFeed: [Blog: How we Sign and Verify Falco Plugins and Rules](<https://devfeed.tech/articles/blog-how-we-sign-and-verify-falco-plugins-and-rules-32523.md>)

Original publisher: [Read original article](<https://falco.org/blog/sign-verify-plugins-rules/>)

Published: 2023-10-18T00:00:00Z

Content type: article

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [branch-protection-rules](<https://devfeed.tech/tags/branch-protection-rules.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [falco](<https://devfeed.tech/tags/falco.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [rules](<https://devfeed.tech/tags/rules.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article explains how Falco v0.36.0, falcoctl 0.6.1, and the 0.7.0 Helm chart improve the security of Falco plugins and rule sets. It describes their OCI-based distribution and discusses safeguards against software supply chain attacks, including signing, verification, branch protection, code review, reproducible builds, dependency pinning, build isolation, and MFA.

### Source excerpt

Falco v0.36.0 and the Software Supply Chain (SSC) security The latest stable Falco release, v0.36.0, alongside falcoctl 0.6.1 and the 0.7.0 Helm chart introduced new features and improvements to the security of Falco's software supply chain artifacts. Falco's two main downloadable artifacts are plugins and rule sets. They're shipped in the OCI specification format and distributed through the official Falcosecurity OCI repositories. Software supply chain attacks aim at injecting malicious code into software components, to compromise downstream users. These types of attacks are among the primary threats in today's threat landscape. In particular, attackers abuse trust relationships existing between the different open-source stakeholders. The increase in attacks on open-source software throughout the last few years demonstrates that attackers consider them a viable means for spreading malware. SSC safeguards Securing the software supply chain may seem daunting at first glance, but there are a lot of safeguards that can be put in action. And there are ways to categorize them, and ways to prioritize them. Safeguards against supply chain attacks can be classified by control type: directive, preventive, detective, corrective, and recovery. But there ain't no such thing as a free lunch. Besides safeguard classifications, the utility-to-cost ratio can also be an important factor in deciding where to start in improving the supply chain security of software, and can be pretty easy to measure it. There are cheap preventive safeguards that can be implemented in open source projects especially, where stakeholders platea can be pretty wide considering the contributions. For example, branch protection rules are usually simple per-code repository configurations in providers (e.g. GitHub) and alongside pull request-based flows enforcing code review quorum, are also standard best practices nowadays. The same applies to reproducible builds, dependency pinning, build steps isolation, MF

## Supporter spotlight: Simon Butler on business adoption of Reproducible Builds

DevFeed: [Supporter spotlight: Simon Butler on business adoption of Reproducible Builds](<https://devfeed.tech/articles/supporter-spotlight-simon-butler-on-business-adoption-of-reproducible-builds-34156.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2023/08/01/supporter-spotlight-simon-butler/>)

Published: 2023-08-01T11:00:00Z

Content type: article

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [data](<https://devfeed.tech/topics/data.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>)

Tags: [adoption](<https://devfeed.tech/tags/adoption.md>), [builds](<https://devfeed.tech/tags/builds.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [research](<https://devfeed.tech/tags/research.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [spotlight](<https://devfeed.tech/tags/spotlight.md>)

### AI overview

This supporter spotlight interviews Simon Butler, a software engineering researcher at the University of Skövde, about a collaborative project with six Swedish businesses that use open source software. The project's paper examines the businesses' knowledge of, experience with, and perceived value of Reproducible Builds.

### Source excerpt

The Reproducible Builds project relies on several projects, supporters and sponsors for financial support, but they are also valued as ambassadors who spread the word about our project and the work that we do. This is the seventh instalment in a series featuring the projects, companies and individuals who support the Reproducible Builds project. We started this series by featuring the Civil Infrastructure Platform project, and followed this up with a post about the Ford Foundation as well as recent ones about ARDC, the Google Open Source Security Team (GOSST), Bootstrappable Builds, the F-Droid project and David A. Wheeler. Today, however, we will be talking with Simon Butler, an associate senior lecturer in the School of Informatics at the University of Skövde, where he undertakes research in software engineering that focuses on IoT and open source software, and contributes to the teaching of computer science to undergraduates. Chris: For those who have not heard of it before, can you tell us more about the School of Informatics at Skövde University? Simon: Certainly, but I may be a little long-winded. Skövde is a city in the area between the two large lakes in southern Sweden. The city is a busy place. Skövde is home to the regional hospital, some of Volvo's manufacturing facilities, two regiments of the Swedish defence force, a lot of businesses in the Swedish computer games industry, other tech companies and more. The University of Skövde is relatively small. Sweden's large land area and low population density mean that regional centres such as Skövde are important and local universities support businesses by training new staff and supporting innovation. The School of Informatics has two divisions. One focuses on teaching and researching computer games. The other division encompasses a wider range of teaching and research, including computer science, web development, computer security, network administration, data science and so on. Chris: You recently had a ope

## Reproducible Builds Summit 2023 in Hamburg

DevFeed: [Reproducible Builds Summit 2023 in Hamburg](<https://devfeed.tech/articles/reproducible-builds-summit-2023-in-hamburg-34155.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2023/07/05/reproducible-builds-hamburg-meeting/>)

Published: 2023-07-05T00:00:00Z

Content type: release

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [builds](<https://devfeed.tech/topics/builds.md>)

Tags: [berlin](<https://devfeed.tech/tags/berlin.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [developers](<https://devfeed.tech/tags/developers.md>), [event](<https://devfeed.tech/tags/event.md>), [germany](<https://devfeed.tech/tags/germany.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [summit](<https://devfeed.tech/tags/summit.md>)

### AI overview

The article announces the Reproducible Builds Summit 2023, scheduled for October 31 to November 2 in Hamburg, Germany. It describes the event's goals, including sharing project updates, improving collaboration, expanding the effort, and developing tools and strategies for reproducible builds.

### Source excerpt

We are glad to announce the upcoming Reproducible Builds Summit, set to take place from October 31st to November 2nd, 2023, in the vibrant city of Hamburg, Germany. This year, we are thrilled to host the seventh edition of this exciting event following the success of previous summits in various iconic locations around the world, including Venice (2022), Marrakesh (2019), Paris (2018), Berlin (2017), Berlin (2016) Athens (2015). If you're excited about joining us this year, please make sure to read the event page which has more details about the event and location. As in previous years, we will be sending invitations to all those who attended our previous summit events or expressed interest to do so. However also without receiving such a personal invitation please do email the organizers and we will find a way to accommodate you. About the event The Reproducible Builds Summit is a unique gathering that brings together attendees from diverse projects, united by a shared vision of advancing the Reproducible Builds effort. During this enriching event, participants will have the opportunity to engage in discussions, establish connections and exchange ideas to drive progress in this vital field. Our aim is to create an inclusive space that fosters collaboration, innovation and problem-solving. With your help, we will bring this space (and several other inside areas) into life: The outside area at dock-europe (source: dock-europe.net) Schedule Although the exact content of the meeting will be shaped by the participants, the main goals will include: Update & exchange about the status of reproducible builds in various projects. Improve collaboration both between and inside projects. Expand the scope and reach of reproducible builds to more projects. Work together and hack on solutions. Establish space for more strategic and long-term thinking than is possible in virtual channels. Brainstorm designs on tools enabling users to get the most benefits from reproducible builds. Di

## Supporter spotlight: David A. Wheeler on supply chain security

DevFeed: [Supporter spotlight: David A. Wheeler on supply chain security](<https://devfeed.tech/articles/supporter-spotlight-david-a-wheeler-on-supply-chain-security-34154.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2022/12/15/supporter-spotlight-davidawheeler-supply-chain-security/>)

Published: 2022-12-15T12:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [linux foundation](<https://devfeed.tech/topics/linux-foundation.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [compilers](<https://devfeed.tech/topics/compilers.md>)

Tags: [compilers](<https://devfeed.tech/tags/compilers.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

An interview with David A. Wheeler, the Linux Foundation's Director of Open Source Supply Chain Security, about improving security across open source software development, builds, distribution, and use. It also discusses reproducible builds and Diverse Double-Compiling as a way to detect trusting trust attacks.

### Source excerpt

The Reproducible Builds project relies on several projects, supporters and sponsors for financial support, but they are also valued as ambassadors who spread the word about our project and the work that we do. This is the sixth instalment in a series featuring the projects, companies and individuals who support the Reproducible Builds project. We started this series by featuring the Civil Infrastructure Platform project and followed this up with a post about the Ford Foundation as well as a recent ones about ARDC, the Google Open Source Security Team (GOSST), Jan Nieuwenhuizen on Bootstrappable Builds, GNU Mes and GNU Guix and Hans-Christoph Steiner of the F-Droid project. Today, however, we will be talking with David A. Wheeler, the Director of Open Source Supply Chain Security at the Linux Foundation. Holger Levsen: Welcome, David, thanks for taking the time to talk with us today. First, could you briefly tell me about yourself? David: Sure! I'm David A. Wheeler and I work for the Linux Foundation as the Director of Open Source Supply Chain Security. That just means that my job is to help open source software projects improve their security, including its development, build, distribution, and incorporation in larger works, all the way out to its eventual use by end-users. In my copious free time I also teach at George Mason University (GMU); in particular, I teach a graduate course on how to design and implement secure software. My background is technical. I have a Bachelor's in Electronics Engineering, a Master's in Computer Science and a PhD in Information Technology. My PhD dissertation is connected to reproducible builds. My PhD dissertation was on countering the 'Trusting Trust' attack, an attack that subverts fundamental build system tools such as compilers. The attack was discovered by Karger & Schell in the 1970s, and later demonstrated & popularized by Ken Thompson. In my dissertation on 'trusting trust' I showed that a process called 'Diverse Double-Comp

## Reproducible builds with GoReleaser

DevFeed: [Reproducible builds with GoReleaser](<https://devfeed.tech/articles/reproducible-builds-with-goreleaser-37761.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/goreleaser-reproducible-buids/>)

Author: Carlos Alexandro Becker

Published: 2022-04-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [builds](<https://devfeed.tech/topics/builds.md>), [Go](<https://devfeed.tech/topics/go.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [builds](<https://devfeed.tech/tags/builds.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [go](<https://devfeed.tech/tags/go.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>)

### AI overview

This tutorial explains how GoReleaser can help produce reproducible Go binary builds by controlling timestamps, build paths, repository state, dependencies, and tool versions. It notes that the Go version must also be pinned, for example in GitHub Actions.

### Source excerpt

GoReleaser can help you, to some extent, to have reproducible builds.

## Finding Non-determinism with nixbuild.net

DevFeed: [Finding Non-determinism with nixbuild.net](<https://devfeed.tech/articles/finding-non-determinism-with-nixbuild-net-34135.md>)

Original publisher: [Read original article](<https://blog.nixbuild.net/posts/2021-01-13-finding-non-determinism-with-nixbuild-net.html>)

Author: support@nixbuild.net

Published: 2021-01-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [nixbuild.net blog](<https://devfeed.tech/sources/nixbuild-net-blog.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [reproducibility](<https://devfeed.tech/topics/reproducibility.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [builds](<https://devfeed.tech/topics/builds.md>), [content addressed store](<https://devfeed.tech/topics/content-addressed-store.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [build](<https://devfeed.tech/tags/build.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>)

### AI overview

This blog post explains how to use Nix repeated builds to detect non-deterministic outputs by comparing build results bit for bit. It also describes how nixbuild.net records repeated-build results and can help investigate failures from past builds.

### Source excerpt

During the last decade, many initiatives focussing on making builds reproducible have gained momentum. reproducible-builds.org is a great resource for anyone interested in how the work progresses in multiple software communities. r13y.com tracks the current reproducibility metrics in NixOS. Nix is particularly suited for working on reproducibility, since it by design isolates builds and comes with tools for finding non-determinism. The Nix community also works on related projects, like Trustix and the content-addressed store. This blog post summarises how nixbuild.net can be useful for finding non-deterministic builds, and announces a new feature related to reproducibility! Repeated Builds The way to find non-reproducible builds is to run the same build multiple times and check for any difference in results, when compared bit-for-bit. Since Nix guarantees that all inputs will be identical between the runs, just finding differing output results is enough to conclude that a build is non-deterministic. Of course, we can never prove that a build is deterministic this way, but if we run the build many times, we gain a certain confidence in it. To run a Nix build multiple times, simply add the -repeat option to your build command. It will run your build the number of extra times you specify. Suppose we have the following Nix expression in deterministic.nix: let inherit (import <nixpkgs> {}) runCommand; in { stable = runCommand "stable" {} '' touch $out ''; unstable = runCommand "unstable" {} '' echo $RANDOM > $out ''; } We can run repeated builds like this (note that the --builders "" option is there to force a local build, to not use nixbuild.net): $ nix-build deterministic.nix --builders "" -A stable --repeat 1 these derivations will be built: /nix/store/0fj164aqyhsciy7x97s1baswygxn8lzf-stable.drv building '/nix/store/0fj164aqyhsciy7x97s1baswygxn8lzf-stable.drv' (round 1/2)... building '/nix/store/0fj164aqyhsciy7x97s1baswygxn8lzf-stable.drv' (round 2/2)... /nix/store/65

## GoReleaser: 4 years releasing software

DevFeed: [GoReleaser: 4 years releasing software](<https://devfeed.tech/articles/goreleaser-4-years-releasing-software-37747.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/goreleaser-4-years/>)

Author: Carlos Alexandro Becker

Published: 2021-01-07T00:00:00Z

Content type: opinion

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [Software](<https://devfeed.tech/topics/software.md>), [Go](<https://devfeed.tech/topics/go.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [docker images](<https://devfeed.tech/topics/docker-images.md>), [MkDocs](<https://devfeed.tech/topics/mkdocs.md>), [Refactoring](<https://devfeed.tech/topics/refactoring.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [parquet](<https://devfeed.tech/topics/parquet.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [apple-silicon](<https://devfeed.tech/tags/apple-silicon.md>), [compression](<https://devfeed.tech/tags/compression.md>), [docker-images](<https://devfeed.tech/tags/docker-images.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [go](<https://devfeed.tech/tags/go.md>), [hooks](<https://devfeed.tech/tags/hooks.md>), [linux](<https://devfeed.tech/tags/linux.md>), [refactoring](<https://devfeed.tech/tags/refactoring.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

A four-year retrospective on GoReleaser describes improvements made over the previous year, including deprecated-setting removal, package signing and creation, build hooks, compression, shell completions, GitHub Actions migration, reproducible builds, and multi-architecture Docker image support. It also notes an Apple Silicon support pull request awaiting the Go 1.16 release.

### Source excerpt

Last year, I made a blog post about GoReleaser turning 3 years old.

## Modules Part 03: Minimal Version Selection

DevFeed: [Modules Part 03: Minimal Version Selection](<https://devfeed.tech/articles/modules-part-03-minimal-version-selection-22155.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2019/12/modules-03-minimal-version-selection.html>)

Published: 2019-12-18T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [modules](<https://devfeed.tech/topics/modules.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Algorithm](<https://devfeed.tech/topics/algorithm.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [ardan-labs](<https://devfeed.tech/tags/ardan-labs.md>), [blog](<https://devfeed.tech/tags/blog.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [dependency-management](<https://devfeed.tech/tags/dependency-management.md>), [go](<https://devfeed.tech/tags/go.md>), [go-programming](<https://devfeed.tech/tags/go-programming.md>), [golang](<https://devfeed.tech/tags/golang.md>), [modules](<https://devfeed.tech/tags/modules.md>), [programming](<https://devfeed.tech/tags/programming.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>)

### AI overview

This tutorial explains Go's Minimal Version Selection algorithm for choosing dependency versions. It contrasts MVS with approaches that select the latest version and illustrates how multiple modules can require different versions of a shared dependency.

### Source excerpt

Series Index Why and What Projects, Dependencies and Gopls Minimal Version Selection Mirrors, Checksums and Athens Gopls Improvements Vendoring Introduction Every dependency management solution has to solve the problem of picking a version of a dependency. Many of the version selection algorithms that exist today attempt to identify the "latest greatest" version of any dependency. This makes sense if you believe semantic versioning will be applied correctly and the social contract will be respected. In these cases, the "latest greatest" version of a dependency should be the most stable and secure version and should have backwards compatibility with earlier versions. At least in the same major version dependency tree.

## Manage Dependencies With GODEP

DevFeed: [Manage Dependencies With GODEP](<https://devfeed.tech/articles/manage-dependencies-with-godep-22080.md>)

Original publisher: [Read original article](<https://www.ardanlabs.com/blog/2013/10/manage-dependencies-with-godep.html>)

Published: 2013-10-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [William Kennedy](<https://devfeed.tech/sources/william-kennedy.md>)

Topics: [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [Code](<https://devfeed.tech/topics/code.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [ardan-labs](<https://devfeed.tech/tags/ardan-labs.md>), [blog](<https://devfeed.tech/tags/blog.md>), [build](<https://devfeed.tech/tags/build.md>), [code](<https://devfeed.tech/tags/code.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [git](<https://devfeed.tech/tags/git.md>), [git-commit](<https://devfeed.tech/tags/git-commit.md>), [go](<https://devfeed.tech/tags/go.md>), [go-programming](<https://devfeed.tech/tags/go-programming.md>), [golang](<https://devfeed.tech/tags/golang.md>), [import](<https://devfeed.tech/tags/import.md>), [install](<https://devfeed.tech/tags/install.md>), [management](<https://devfeed.tech/tags/management.md>), [packages](<https://devfeed.tech/tags/packages.md>), [programming](<https://devfeed.tech/tags/programming.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [version-control](<https://devfeed.tech/tags/version-control.md>)

### AI overview

This tutorial explains how to use godep to manage third-party Go dependencies and create reproducible builds. It covers installing godep, creating a project, generating a Godeps file with dependency version information, and vendoring packages.

### Source excerpt

Introduction If you are using 3rd party packages, (packages that you don't own or control), you will want a way to create a reproducible build every time you build your projects. If you use 3rd party packages directly and the package authors change things, your projects could break. Even if things don't break, code changes could create inconsistent behavior and bugs. Keith Rarick's tool godep is a great step in the right direction for managing 3rd party dependencies and creating reproducible builds. The godep tool gives you two options for managing dependencies. The first option creates a dependency file with version control information and then with some godep magic, the code is built against those versions. You can also Vendor your 3rd party packages inside your projects as well. You never need to change a single source code file and everything is accomplished in conjunction with the go tooling. Downloading Godep Download godep using go get and make sure your $GOPATH/bin directory is in your PATH. go get github.com/kr/godep export PATH=$PATH:$GOPATH/bin Create A Project Build your project using the 3rd party packages as you normally would. Since godep does not require you to change any import paths in the code, 'go get' the code you need and import those packages directly. To keep the post simple, I am going to use an existing program called News Search that uses one 3rd party dependency. export GOPATH=$HOME/example go get github.com/goinggo/newssearch View linked image: Screen Shot