Event JSON
{
"id": "94a50b9abd557ffce9728acbe02c81d940146f0214c44c7c81689d6cdb8a6053",
"pubkey": "1c916e3126795bb0d5ae867e590cca6f61e7359762647d2847427b23b541e04b",
"created_at": 1731649491,
"kind": 1,
"tags": [
[
"p",
"4ebb1885240ebc43fff7e4ff71a4f4a1b75f4e296809b61932f10de3e34c026b",
"wss://relay.mostr.pub"
],
[
"p",
"8b0be93ed69c30e9a68159fd384fd8308ce4bbf16c39e840e0803dcb6c08720e",
"wss://relay.mostr.pub"
],
[
"e",
"240a3470fcabb81862cd956fd1011bf35623c320e667a9996a294548ae933bda",
"wss://relay.mostr.pub",
"reply"
],
[
"proxy",
"https://fosstodon.org/users/whynothugo/statuses/113485381092079376",
"activitypub"
]
],
"content": "nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqf6a33pfyp67y8llhunlhrf855xm47n3fdqymvxfj7yx78c6vqf4sy8ssyg I understand what this does, but I don’t understand the value of it. It provides validation that the build happened on MS’s server and that they used used a specific checkout. But if builds are not reproducible (eg: use unchecksumed external resources), this guarantees nothing. If builds are properly reproducible, what value does the attestation add?",
"sig": "16c3d93b80357969780392fbaf284077c4bec0a3aee6cd9d8bbdf4be93003aebe0f3088aedc14e73b385cc1a005b26d565002424adc47357258388c77d015acb"
}