Introducing OSS Rebuild: Open Source, Rebuilt to Last
ID: 690267a3-e386-51b7-9df8-869f8c42f355
STIX ID: report--690267a3-e386-51b7-9df8-869f8c42f355
Feed Name: Google Online Security Blog
This report announces OSS Rebuild, a project aimed at strengthening software supply chain security by automatically rebuilding packages from PyPI, npm, and Crates.io to produce SLSA Level 3 provenance and detailed build observability. It describes how the platform derives declarative build definitions, semantically compares artifacts, detects anomalies (e.g., unsubmitted source, compromised build environments, stealthy backdoors), and integrates with existing workflows while offering a CLI for fetching and rebuilding attestations. The initiative seeks to empower security teams and maintainers with verifiable builds, enhanced metadata, and the ability to augment SBOMs without burdening upstream publishers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
