Reproducible builds make unexpected differences visible
If building the same source twice produces identical output, then any difference is a signal.
That turns tampering into something detectable rather than something you have to trust the pipeline about. Achieving it is fiddly, because timestamps, paths and ordering all creep in. The payoff is being able to verify independently that a published artefact matches its stated source.
More on Software supply chain
- A trusted build can faithfully ship malicious sourceThe oven never reads the recipe
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
