Reach compiler and Docker runtime: who should own image version pinning for reproducible builds?
Integration boundary We are adopting Reach (reach.sh) for a DApp project and want a repeatable development environment across laptops and CI. Reach distributes its compiler and standard library as Docker images invoked through the ./reach wrapper script, so the host only needs Docker. That makes the boundary between the Reach toolchain and the Docker runtime