@dthompson
I'm not sure what you mean here. Patching a binary extracted from a sha256 identified tarball seems as reproducible as you can get (for a pre-built binary).
Sure it's not from source, but it is entirely reproducible. Now... I wouldn't call that a build 😋