box-project/box

Reproducible builds improvements

theofidry opened this issue · 5 comments

As per a discussion with seldaek and @drupol:

drupol commented

Cool initiative!

Here's a few comments:

https://box-project.github.io/box/reproducible-builds/#composer-autoload-suffix could be automatically set by Box (e.g. to the commit reference) or recommend to commit the composer.lock (probably simpler)

This is not needed any more if the project ships a composer.lock file, see: composer/composer#11663

https://box-project.github.io/box/reproducible-builds/#timestamp: The timestamp could be forced and default to the one of the commit

AFAIK, I was unable to use that option.

AFAIK, I was unable to use that option.

How come? 🤔

drupol commented

I don't know, am I doing something wrong?

image

drupol commented

Oh never mind, you just tagged that feature for 4.6.0 !

Indeed, unfortunately the docs are not versioned :/