Arch Linux now has a bit-for-bit reproducible Docker image
https://lists.archlinux.org/archives/list/arch-dev-public@lists.archlinux.org/thread/44PW52T547MACXFU5HZ5U7SIPAX3BAXS/Article
- Arch Linux Docker image is now bit-for-bit reproducible
- Caveat: pacman keys stripped to achieve reproducibility; keyring must be regenerated manually
- Milestone for supply-chain integrity in container base images
Discussion
- Commenters ask why reproducibility matters; thread explains supply-chain attack prevention
- Stripped pacman keys mean image isn’t usable out of the box without keyring init
| Type | Link |
| Added | Apr 22, 2026 |
| Modified | Apr 22, 2026 |