logo

Introducing OSS Rebuild: Open Source, Rebuilt to Last

ID: 690267a3-e386-51b7-9df8-869f8c42f355

STIX ID: report--690267a3-e386-51b7-9df8-869f8c42f355

Feed Name: Google Online Security Blog

Date Published: 2025-07-21

Date Updated: 2026-04-27

Author: Kimberly Samra

...
...

This report announces OSS Rebuild, a project aimed at strengthening software supply chain security by automatically rebuilding packages from PyPI, npm, and Crates.io to produce SLSA Level 3 provenance and detailed build observability. It describes how the platform derives declarative build definitions, semantically compares artifacts, detects anomalies (e.g., unsubmitted source, compromised build environments, stealthy backdoors), and integrates with existing workflows while offering a CLI for fetching and rebuilding attestations. The initiative seeks to empower security teams and maintainers with verifiable builds, enhanced metadata, and the ability to augment SBOMs without burdening upstream publishers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.