How reproducible is NixOS?

Day 1 | 11:10 | 00:20 | K.3.601 | Julien Malka


Note: I'm reworking this at the moment, some things won't work.

The stream isn't available yet! Check back at 11:10.
Get involved in the conversation!Join the chat

Bitwise reproducibility is recognized as a promising way to increase trust in the distribution phase of binary artifact and hence increase trust in the software supply chain. But how reproducible is Nixpkgs? We know that the NixOS ISO image is very close to be perfectly reproducible thanks to reproducible.nixos.org, but there doesn't exist any monitoring of Nixpkgs as a whole. In this talk I'll present the findings of a project that evaluated the reproducibility of Nixpkgs as a whole by mass rebuilding packages from revisions between 2017 and 2023 and comparing the results with the NixOS cache.