Is anyone working on (or thinking of working on) making our build process reproducible?
https://reproducible-builds.org/
It seems Debian and Fedora are already part of the project, and the advantages are quite compelling, not just from a security perspective, but also due to the potential savings in storage and network consumption:
https://hackweek.suse.com/13/projects/131