oss-rebuild

Securing open-source package ecosystems by originating, validating, and augmenting build attestations.

View the Project on GitHub google/oss-rebuild

OSS Rebuild

Secure open-source package ecosystems by originating, validating, and augmenting build attestations.

Overview

OSS Rebuild aims to apply reproducible build concepts at low-cost and high-scale for open-source package ecosystems.

Rebuilds are derived by analyzing the published metadata and artifacts and are evaluated against the upstream package versions. When successful, build attestations are published for the upstream artifacts, verifying the integrity of the upstream artifact and eliminating many possible sources of compromise.

We currently support the following ecosystems:

While complete coverage is the aim, only the most popular packages within each ecosystem are currently rebuilt.

Purpose

Security

To better understand the security properties of rebuilds, see Trust and Rebuilds.

Check out these related projects contributing to the reproducible builds effort:

Disclaimer

This is not an officially supported Google product.