OSS Rebuild validates software package integrity by rebuilding artifacts from source and comparing results, detecting potential supply chain attacks and building trust in open source.
Detect discrepancies between published artifacts and source code, helping identify potential compromises before they impact your systems.
Generate and verify cryptographically signed attestations that provide evidence of build reproducibility.
Continuously rebuild popular packages to ensure they remain free from tampering throughout their lifecycle.
Gain insights into ecosystem health, package reproducibility rates, and common build issues.
Uniform approach across multiple package ecosystems including NPM, PyPI, and Crates.io.
Designed to integrate with CI/CD pipelines and policy enforcement systems.
Analysis of package metadata to identify source repositories, versions, and build parameters.
Secure, isolated rebuilding of packages from source in reproducible environments.
Normalization and comparison of rebuilt artifacts against originals to detect differences.
Generation of cryptographically signed attestations for successful rebuilds.
Start validating your dependencies today with OSS Rebuild.
Get Started