With 25.11 out, it’s time for an update! TL;DR: we can still fully reproduce the minimal installation ISO, and are making steady progress in tracking and exposing attestations. Reproducing the minimal ISO The process I used for rebuilding the minimal ISO while avoiding reliance on the binary cache as much as possible has not materially changed since the previous update: Starting the NixOS 20.03 VirtualBox appliance in qemu (needs more memory than before, notably building clang seems to need m...