Reproducible Builds¶
Lamb, C., & Zacchiroli, S. (2022). Reproducible Builds: Increasing the Integrity of Software Supply Chains. IEEE Software, 39(2), 62-70.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Integrity Checksum or Signature
- The discipline that keeps it honest is to verify the trust root out-of-band, rotate and revoke keys deliberately, and never let "signed" stand in for "reviewed" — which is why reproducible builds matter, since they let a third party rebuild the source
This sourcePresents reproducible builds as independent rebuilding of the same source to produce bit-for-bit identical outputs, checking whether distributed binaries correspond to that source.
- The discipline that keeps it honest is to verify the trust root out-of-band, rotate and revoke keys deliberately, and never let "signed" stand in for "reviewed" — which is why reproducible builds matter, since they let a third party rebuild the source
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:a223c5cbe2e4 · see in the full table