Patrick Winnertz wrote: > Am Dienstag, 18. September 2007 21:12:44 schrieb Julien Cristau: > > > Hmmhh, what do you do about programs etc that encode the build-time in > > > the binary? I mean they obviously will change between builds? > > > > Hopefully they don't encode the build-time in the file list? > We checked not for files which differ, but only for files which are missing > in the first package. or which are missing in the second package. > I think it would be really cool if the Debian policy required that packages could be rebuild bit-identical from source. At the moment, it is impossible to independly verify the integricity of binary packages. Greetings, Martin
Attachment:
signature.asc
Description: Dies ist ein digital signierter Nachrichtenteil