Nit: there’s nothing “cryptographic” about reproducible builds.
“Reproducible build” already usually implies bit-by-bit reproducibility.
I meant with Nix you're comparing hashes. With Docker, you're using pinned versions
i thought it mainly implied architectural/hardware compatibility and deterministic output
I meant with Nix you're comparing hashes. With Docker, you're using pinned versions