@kushal @securedrop Sounds good. It’s roughly what we do for Freenet, though there it’s done by gradle witness β€” and we have a script that can disassemble the release jars and check them against a local build, and the script ignores timestamps: github.com/freenet/scripts/blo

Though nowadays I would prefer to use a Guix setup for this.

