Docs › Security
Biscuit releases are built with Guix, like Bitcoin Core, Monero and Feather. Build the same version from its source and you get the same files, byte for byte. Anyone can check that a release really comes from its published source code, and nothing was added along the way.
The source archive of each release is on the download page, and the build instructions in RELEASE.md in it. You need a Linux computer with Guix. The build takes a while the first time: Guix builds every tool from source.
Then compare the checksums of your files with the signed list, hashes-<version>-plain.txt.
Two parts work differently, and we’d rather you hear it from us:
biscuit-swapd, written in Rust) isn’t built by Guix. We build it separately, and the Guix build won’t continue unless its SHA-256 matches the one recorded in the source code. Its source is in the archive, so you can rebuild it too.