DGV-TC-088L9: Reproducibility & AuditGER-288: Build ReproducibilityVersion: 1.0.0
Build-from-Source Verifier Reproducibility
Verifies that the dgv-verifier binary can be built from source and that the resulting binary's SHA-256 matches the published checksum. This proves the binary is reproducible from the open source - no hidden modifications.
Operational Purpose & Scope
The dgv-verifier binary must be buildable from source. The resulting binary's SHA-256 must match the published checksum in CHECKSUMS.txt.
Verification Context
- Target Scope:
dgv-verifier build reproducibility test - Audit Strategy:
build_reproducibility - Verification Metrics:
build_reproduciblechecksum_matches - Framework Origin:DGV L9: Reproducibility & Audit
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
A non-reproducible build means the published binary may differ from the source, undermining the open-source verification claim.
Expected Outcome
- gate_status:
"ALLOW" - residual_final:
0 - indices_healed:
[]
Explore this card in 3D
Open DGV-TC-088 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →