Skip to content

docs: document reproducible release builds - #26

Merged
zefutoff merged 1 commit into
mainfrom
docs/reproducible-release-build
Oct 9, 2026
Merged

zefutoff merged 1 commit into
mainfrom
docs/reproducible-release-build

Conversation

@zefutoff

@zefutoff zefutoff commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Summary

  • document the unsigned release build procedure
  • define the project's byte-for-byte reproducibility criteria
  • add a reusable two-worktree reproducibility checker
  • add make release-reproducibility
  • document the pinned Gradle, Android, Kotlin and Grammalecte build inputs
  • document the release APK privacy and SHA-256 verification steps
  • clearly separate unsigned-build reproducibility from the future signing pipeline
  • update outdated pre-release documentation
  • complete the first Phase 5 roadmap item

Reproducibility validation

The exact PR commit was built twice from separate detached Git worktrees with:

:app:assembleRelease
--no-daemon
--no-build-cache
--no-configuration-cache

Both unsigned APKs produced:

ce3b35dcea664d4247a6cc83fa4e58355fbf3453c206ba5e7c3ade857df64790

Result:

REPRODUCIBLE: unsigned release APK files are byte-for-byte identical.

Validation

  • make check
  • make release-reproducibility
  • git diff --check

Roadmap

Completes:

  • Reproducible release build documentation

@zefutoff
zefutoff merged commit ab3f54d into main Oct 9, 2026
3 checks passed
@zefutoff
zefutoff deleted the docs/reproducible-release-build branch October 9, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant