Skip to content

Harden Linux binary release build reproducibility #1061

@wayyoungboy

Description

@wayyoungboy

Background

PR #1060 adds Linux amd64 standalone binary release assets built in a CentOS 7 container.

Proposal

Pin the Linux binary build inputs more tightly and verify the Miniconda installer checksum in docker/Dockerfile.binaries-centos7.

Motivation

This would make release binary builds more reproducible and improve supply-chain resilience for release assets.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions