Reproducible Builds: Increasing the Integrity of Software Supply Chains

Chris Lamb, Stefano Zacchiroli

Research output: Contribution to journalArticlepeer-review

Abstract

Although it is possible to increase confidence in free and open source software by reviewing its source code, trusting code is not the same as trusting its executable counterparts. This article examines reproducible builds, an approach that can determine whether generated binaries correspond to the original source code.

Original languageEnglish
Pages (from-to)62-70
Number of pages9
JournalIEEE Software
Volume39
Issue number2
DOIs
Publication statusPublished - 1 Jan 2022
Externally publishedYes

Fingerprint

Dive into the research topics of 'Reproducible Builds: Increasing the Integrity of Software Supply Chains'. Together they form a unique fingerprint.

Cite this