Skip to content
NorscodeNorscode

One file, one sum: reproducible releases

ArticleBy the Norscode project

The whole program is linked into one NCB file with a SHA-256 sum, so you can prove what's running.

Everything is linked into one file with one sum app.no std.web std.krypto links program.ncb SHA-256: 3f9a…c1

When you build a finished Norscode program, everything it consists of — your code and the parts of the standard library you actually use — is linked into a single file. That file has a SHA-256 sum: a fingerprint that changes if so much as one character is different.

What it gives you

You can prove that what's running in production is exactly what you built and tested. Not "probably the same" — byte for byte the same. The sum you had when you tested is the sum you check against when you roll out. If they match, there's no doubt.

An answer to a real problem

A large part of modern security breaches doesn't come through your own code, but through the links around it: a dependency that was swapped out, a build chain that added something along the way, a library that was updated to something other than you thought. When the whole program is one file with one sum, there are no hidden links to swap out quietly.

Only what you use

The linking takes along only the parts of the library the program actually calls. The result is smaller, faster to load, and easier to reason about — it isn't a whole ecosystem that comes along, just what you asked for.

Reproducibility sounds technical, but it's about something simple: knowing, not believing, what's running.

How you prove what's running

The checksum isn't just decoration. When you build, the NCB file gets a SHA-256 value — a fingerprint that changes completely if so much as one character in the program is different. If you note the value when you test, you can compare it with the file sitting on the server and know, not believe, that it's exactly the same. If they're equal, there's no doubt; if they differ, you know something has changed.

Only what you use

The linking takes along only the parts of the standard library the program actually calls — the rest is shaken off like dead branches on a tree. The result is smaller, faster to load, and easier to reason about. You don't send a whole ecosystem into production, only the code that actually runs.

An answer to a real problem

A large part of modern security breaches doesn't come through your own code, but through the links around it: a dependency that was quietly swapped out, a build chain that added something along the way. When the whole program is one file with one sum, there are no hidden links left to swap out. It's easier to secure, because there's less to secure.

Related

Back to the overview