Skip to content

Commit

Permalink
Reproducible verification build blog
Browse files Browse the repository at this point in the history
Signed-off-by: Andrew Leonard <[email protected]>
  • Loading branch information
andrew-m-leonard committed Aug 2, 2024
1 parent 9f9de3b commit 9787a39
Showing 1 changed file with 2 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,8 @@ subsequently used to build the Eclipse Temurin binaries.

## Independently fully reproducible Eclipse Temurin

Combining the use of the "gcc DevKit", the well defined Eclipse Temurin build pipeline and the output of the secure development Software Bill
of Materials (SBOM), then allows a documented and independent method for third-parties to perform an identical reproducible build.
Combining the use of the "gcc DevKit", the well defined Eclipse Temurin build pipeline and the generated secure development Software Bill
of Materials (SBOM), allows a documented and independent method for third-parties to perform an identical reproducible build.
By comparing the independently built binary with the official Eclipse Temurin release, any discrepancies or tampering can be detected,
ensuring that the Temurin JDK has been securely and correctly built. These third-party Reproducible builds help maintain trust in the supply chain
by providing a mechanism for independent verification of software integrity of the Eclipse Temurin release binaries.
Expand Down

0 comments on commit 9787a39

Please sign in to comment.