@pixelcode @kkarhan@infosec.space I have followed their #ReproducibleBuilds over the years, they never actually reproduce the whole thing from source, just the easy parts. Last I checked, all their native code is just pulled in as binaries when using their reproducer setup. Plus, they can't reproduce the proprietary Google libraries https://github.com/signalapp/Signal-Android/blob/556bcda58ae65abbba75bf899a43666ba6d9d427/app/build.gradle.kts#L533