Generic CC0 editorial illustration

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers. The project comprises: Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/TS), and Crates.io (Rust) packages. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrat…

Editorial note. This page preserves feed metadata and a bounded excerpt for discovery. It does not reproduce the publisher's complete article.

Open the complete publication at Google Security Blog →

Record details

  • Local record: 5ddb4c3a4dd767c00a77
  • Source feed: Google Security Blog
  • Published: 2025-07-21T21:34:00Z