When I normalize BUILDTIME with `%use_source_date_epoch_as_buildtime`, the 
signature still gives the real date. Is there a value in keeping both? e.g. 
[this 
package](https://build.opensuse.org/package/show/home:bmwiedemann:reproducible/strip-nondeterminism)
 `rpm -ql` has
```
Signature   : RSA/SHA256, 2024-02-26T12:00:49 UTC, Key ID 8adc26dbb49c2121
Source RPM  : strip-nondeterminism-1.13.1-33.9.src.rpm
Build Date  : 2023-07-28T16:19:49 UTC
```
Not overriding BUILDHOST is fine as it still allows easy verification.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/discussions/2934#discussioncomment-8640953
You are receiving this because you are subscribed to this thread.

Message ID: 
<rpm-software-management/rpm/repo-discussions/2934/comments/8640...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to