Introducing OSS Rebuild: Open Source, Rebuilt to Last
Google’s Open Source Security Team has launched OSS Rebuild, a project aimed at enhancing trust in open source package ecosystems by reproducing upstream artifacts. With the rise of supply chain attacks, OSS Rebuild allows security teams to reinforce package integrity without imposing on maintainers. The initiative automates build definitions for popular package registries and provides tools for verification and observability. It enhances transparency in the software supply chain and helps detect compromises, while engaging the community in bolstering open source security.











