DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
If you have a project that is built with Apache Maven, refer to the Configuring for Reproducible Builds guide.
Java / Gradle
...
, Maven and sbt
Refer to the JVM build tools documentation on reproducible-builds.org.
Gradle builds may require setting some options in the build to ensure reproducible artifacts. Using the file-system permissions can be fine, but consider that different users (and OS's) may have different umask settings/defaults.
// This is applied to all Jar, Zip and Tar tasks.
tasks.withType<AbstractArchiveTask>().configureEach {
isPreserveFileTimestamps = false
isReproducibleFileOrder = true
// consistent directory permissions, ignoring system's umask
dirPermissions { unix("755") }
// consistent file permissions, ignoring system's umask, retaining the executable permission (either 644 or 755)
filePermissions {
user.read = true
user.write = true
group.read = true
group.write = false
other.read = true
other.write = false
}
}
Java / .properties files
All Java properties generated using java.util.Properties.store() contain a comment line with the generation timestamp. This varying content breaks reproducible builds.
Consider setting the Java system property java.properties.date to some fixed value in your build scripts.
For Gradle, consider adding a line like the following to gradle.properties.
systemProp.java.properties.date=Your project's commentJava / character set + locales
When building with Java 17 or older, consider setting file.encoding=UTF-8. UTF-8 is the default since Java 18.
Other system properties to consider depending on your build requirements: user.language=en, user.country=US, user.variant= (empty)
Python
Modern Python tooling (such as Flit and Hatch) support reproducible builds for pure-Python projects. You can read more about reproducible build support in Flit reproducible build docs and Hatch reproducible build docs. It's a bit more complex if your assets require native compilation, but if you can assure that your native compilation produces reproducible libraries on its own the packaging tool will produce reproducible builds..
...
The helm package command from Helm versions before 4.0.0 cannot produce non- reproducible archives.
Since Helm version 4.0.0, it is possible to produce reproducible archives, even with the --sign option. The package archive entries get a constant uid/gid and fixed POSIX permissions. The file modification time is set to the source files' modification time.
Consider setting a constant file modification time, for example using find $PACKAGE_CONTENTS_DIRECTORY -exec touch -d "2000-01-01 00:00:00" {} +
...
3) Consider using a fixed mtime and not using git-archive's gzip. For example: git archive --mtime="1980-02-01 00:00:00 UTC" --format=tar HEAD | gzip -6 --no-name > my-archive.tar.gz
...