Skip to content

[1.8] Reproducible builds, artifact signing, and SBOM outputs #8

@mikejmorgan-ai

Description

@mikejmorgan-ai

Implement deterministic builds for .deb and ISO, pinned toolchains, hermetic environments, reprotest/diffoscope validation, build attestations (SLSA/in-toto), artifact signing, key management, SBOM generation (SPDX/CycloneDX), and offline verification.

Scope

This epic covers 13 decisions and 10 tasks from the Cortex Linux planning system.

Source

  • Planning Tool: Skilliks
  • Module: See internal planning documentation

Tasks

Tasks will be added as sub-issues or checklist items as specification is refined.


Epic generated from Cortex Linux strategic planning

Metadata

Metadata

Assignees

No one assigned

    Labels

    P2-mediumv1.0 features - medium priorityepicEpic: major feature area with subtasks

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions