in last week’s email to the reproducible-builds email list1 about reproducible Arch Linux I mentioned there’s only one unreproducible package left in docker.io/library/archlinux.
Due to amazing work by dvzrv and Foxboron this package is now also reproducible!
INFO arch_repro_status > All packages are reproducible!
INFO arch_repro_status > Your system is 100.00% reproducible.
To try for yourself use:
podman run --rm -t archlinux sh -c 'pacman -Suy arch-repro-status 
--noconfirm && arch-repro-status'
- This is dope, but I’ve been curious, what benefits are there to this? I know reproducibility can improve security by proving that the distro is delivering the packages they say they are, but is there anything else? - It also helps a bit with debugging because it reduces discrepancies by ensuring that the output of a build is consistently the same when compiled from the same source code and tools, regardless of the machine or environment. 
 



