Arch Linux provides reproducible builds of container images.

The Arch Linux distribution provides reproducible container image builds, ensuring that the binaries included in the image are compiled from the provided source code and contain no hidden modifications. Reproducible Arch Linux images are hosted on Docker Hub under the tag repro. Anyone can build a bit-for-bit identical container image from the source code that matches the prebuilt images released by the project and verify that the distribution's build infrastructure, compiler, and build tools are not compromised.

When creating reproducible builds, details such as exact dependency matches, the use of immutable build tool compositions and versions, identical sets of options and default settings, preservation of the order of file assembly (applying the same sorting methods), and disabling the compiler from adding non-deterministic metadata like random values, file path references, and build date and time data are taken into account. Build reproducibility can also be affected by toolchain bugs and race conditions.

Reproducible images are supplied separately because full reproducibility is ensured by excluding keys for the pacman package manager from their composition. If there's a need to update or install packages through pacman in these images, it's necessary to run the command to recreate the key store (‘pacman-key --init && pacman-key --populate archlinux’). To check the identity of one's own build against the image distributed via Docker Hub, one can compare the hashes produced by the command ‘podman inspect --format '{{.Digest}}' ’, or use the diffoci tool.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster