Zero-trust builds for FreeBSD
The FreeBSD Foundation has announced that it has undertaken a project to deliver zero-trust builds commissioned by the Sovereign Tech Agency (STA).
The Zero-Trust Build project is scheduled from Jan-Aug 2025 and centers on the FreeBSD build process, and in particular, release building. The primary goal of this work is to enable the entire release process to run without requiring root access, and that build artifacts build reproducibly – that is, that a third party can build bit-for-bit identical artifacts.
Additionally, the project aims to enhance build process documentation, ensuring that release building is straightforward and does not require specialized knowledge. The work is targeted for completion prior to the release of FreeBSD 15.0.
The Foundation says that updates should not impact users of FreeBSD release images, but it may have an impact on developers basing projects or products on FreeBSD that make modifications to its release process.
Posted Jan 22, 2025 21:32 UTC (Wed)
by ibukanov (subscriber, #3942)
[Link] (1 responses)
Posted Jan 23, 2025 21:23 UTC (Thu)
by jrtc27 (subscriber, #107748)
[Link]
Posted Jan 23, 2025 4:59 UTC (Thu)
by brunowolff (guest, #71160)
[Link]
Posted Jan 23, 2025 7:05 UTC (Thu)
by pabs (subscriber, #43278)
[Link] (1 responses)
https://lwn.net/Articles/983340/
Posted Jan 26, 2025 1:22 UTC (Sun)
by Lennie (subscriber, #49641)
[Link]
But you probably have to get these steps done first before you can think about the others. Maybe not for a strictly technical reason, but from a sense of logical ordering.
Posted Jan 23, 2025 13:54 UTC (Thu)
by amacater (subscriber, #790)
[Link]
Cross-compilation
Cross-compilation
Reproducible builds improve privacy of the builder
Bootstrappable?
https://bootstrappable.org/
Bootstrappable?
Reproducible builds for FreeBSD