nostr:note1dc5yk2c27ltc0xm8ussdnnk20c7jq88ru4der35etez6rqk44f6sr8k4t7
Our releases feature reproducible builds, meaning that you can build the release yourself and VERIFY that the release images are an EXACT bit-for-bit match to your result.
This means that we can't sneak secret code into a release. Our FOSS code and build process are out in the open for anyone to view and repeat.
And going forward, the major contributors will make our own attestations to verify the expected hashes. This further distributes the trust model if multiple sources are verifying the same results.
My personal attestation:

Compare the hashes against what's on the github release page:
https://github.com/SeedSigner/seedsigner/releases/download/0.8.5/seedsigner.0.8.5.sha256.txt
Discussion
No replies yet.