Reproducible Builds: Increasing the Integrity of Software Supply Chains - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Article Dans Une Revue IEEE Software Année : 2021

Reproducible Builds: Increasing the Integrity of Software Supply Chains

Résumé

Although it is possible to increase confidence in Free and Open Source Software (FOSS) by reviewing its source code, trusting code is not the same as trusting its executable counterparts. These are typically built and distributed by third-party vendors, with severe security consequences if their supply chains are compromised. In this paper, we present reproducible builds, an approach that can determine whether generated binaries correspond with their original source code. We first define the problem, and then provide insight into the challenges of making real-world software build in a "reproducible" manner-this is, when every build generates bit-for-bit identical results. Through the experience of the Reproducible Builds project making the Debian Linux distribution reproducible, we also describe the affinity between reproducibility and quality assurance (QA).
Fichier principal
Vignette du fichier
SW-2020-12-0293.R1_Zacchiroli.pdf (432.69 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03196519 , version 1 (12-04-2021)

Identifiants

Citer

Chris Lamb, Stefano Zacchiroli. Reproducible Builds: Increasing the Integrity of Software Supply Chains. IEEE Software, In press, ⟨10.1109/MS.2021.3073045⟩. ⟨hal-03196519⟩

Collections

INRIA
91 Consultations
217 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More