MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
rebuild
Recherche

Google launches OSS Rebuild

mardi 22 juillet 2025, 15:51 , par LWN.net
Google has announced
the existence of OSS Rebuild, an infrastructure for the creation and
verification of reproducible builds of software projects.

Our aim with OSS Rebuild is to empower the security community to
deeply understand and control their supply chains by making package
consumption as transparent as using a source repository. Our
rebuild platform unlocks this transparency by utilizing a
declarative build process, build instrumentation, and network
monitoring capabilities which, within the SLSA Build framework,
produces fine-grained, durable, trustworthy security metadata.

Our vision extends beyond any single ecosystem: We are committed to
bringing supply chain transparency and security to all open source
software development. Our initial support for the PyPI (Python),
npm (JS/TS), and Crates.io (Rust) package registries—providing
rebuild provenance for many of their most popular packages—is just
the beginning of our journey.
https://lwn.net/Articles/1030935/

Voir aussi

News copyright owned by their original publishers | Copyright © 2004 - 2025 Zicos / 440Network
Date Actuelle
mer. 23 juil. - 15:11 CEST