* a full checkout of libressl: http://git.sta.li/src/tree/lib/libressl
* a full checkout of expat: http://git.sta.li/src/tree/lib/expat
* two full /bins: http://git.sta.li/rootfs-x86_64/tree/bin http://git.sta.li/rootfs-pi/tree/bin
The point was that you can verify the integrity by reading the source code. The actual limits to this depend on many things.
* a full checkout of libressl: http://git.sta.li/src/tree/lib/libressl
* a full checkout of expat: http://git.sta.li/src/tree/lib/expat
* two full /bins: http://git.sta.li/rootfs-x86_64/tree/bin http://git.sta.li/rootfs-pi/tree/bin