Introducing OSS Rebuild: Open Source, Rebuilt to Last
Google's Open Source Security Team announced OSS Rebuild, a new project that strengthens trust in open source package ecosystems by reproducing upstream artifacts and generating SLSA provenance for PyPI, npm, and Crates.io packages. The tool detects supply chain compromises including unsubmitted source code, build environment tampering, and stealthy backdoors, providing security teams with verifiable build metadata to prevent package compromise without burdening maintainers. OSS Rebuild is available as open source with a Go CLI and web interface for exploring rebuilt packages and their provenance.
Summary
Google's Open Source Security Team announced OSS Rebuild, a new project that strengthens trust in open source package ecosystems by reproducing upstream artifacts and generating SLSA provenance for PyPI, npm, and Crates.io packages. The tool detects supply chain compromises including unsubmitted source code, build environment tampering, and stealthy backdoors, providing security teams with verifiable build metadata to prevent package compromise without burdening maintainers. OSS Rebuild is available as open source with a Go CLI and web interface for exploring rebuilt packages and their provenance.
Indicators of Compromise
- malware — xz-utils
- malware — solana/webjs
- malware — tj-actions/changed-files