Get the latest tech news
Is NixOS truly reproducible?
Julien Malka homepage
One direct application of reproducible-builds is increasing trust in the software supply chain by allowing users to independently verify the trustworthiness of binaries they download. We then compared the output with the ground truth (historical builds from Hydra, the nixpkgs continuous integration) to determine if the package is bitwise reproducible or not. The high reproducibility rate in our most recent revision is quite impressive, given both the size of the package set and the absence of systematic monitoring in nixpkgs.
Or read this on Hacker News