Google Online Security Blog
Follow
Introducing OSS Rebuild: Open Source, Rebuilt to Last
The Google Open Source Security Team has announced OSS Rebuild, a project aimed at strengthening trust in open source package ecosystems by reproducing upstream artifacts. The project provides automation to derive declarative build definitions, SLSA Provenance for thousands of packages, and build observability and verification tools. OSS Rebuild helps security teams avoid compromise without burdening upstream maintainers. Open source software has become the foundation of our digital world, but its ubiquity makes it an attractive target for supply chain attacks. Recent high-profile attacks have eroded trust in open ecosystems, creating hesitation among contributors and consumers. OSS Rebuild empowers the security community to deeply understand and control their supply chains by making package consumption transparent. The project uses a declarative build process, build instrumentation, and network monitoring capabilities to produce fine-grained, durable, trustworthy security metadata. OSS Rebuild can detect several classes of supply chain compromise, including unsubmitted source code, build environment compromise, and stealthy backdoors. The project provides capabilities for enterprises, security professionals, publishers, and maintainers of open source packages to enhance metadata, augment SBOMs, and accelerate vulnerability response. OSS Rebuild invites developers, enterprises, and security researchers to get involved and contribute to improving support for critical ecosystems and packages.