reproducible builds
it would be nice to have reproducible builds for wallabako. because we can't upload x86 binary builds, there's no public trust path for those on Gitlab. if we could reproduce the CI build, we could sign that and it would complete the loop. Someone has written an interesting article regarding reproducible builds in go: basically, builds are reproducible by default. And because we're using the go compiler (and not GCC) for the x86 build, we should be able to get away with this. But we're using a different golang version and probably a bunch more environment in CI than on my desktop, so I need to look at what's different there.