OSS Rebuild icon
OSS Rebuild icon

OSS Rebuild

Securing open-source package ecosystems by originating, validating, and augmenting build attestations.

OSS Rebuild screenshot 1

Cost / License

  • Free
  • Open Source

Platforms

  • Go (Programming Language)
  • Linux
  • Mac
  • Windows
  • BSD
-
No reviews
3likes
0comments

Features

Suggest and vote on features

Properties

  1.  Security-focused

Features

  1.  CI/CD
  2.  NPM

 Tags

  • pipeline-integration
  • integrity-check
  • supply-chain-software
  • rebuild
  • supply-chain-management
  • Supply Chain Security
  • source-code-analysis
  • software-supply-chain-security
  • integrity
  • pypi
  • data-integrity
  • file-integrity

OSS Rebuild News & Activities

Highlights All activities

Recent News

Show more news

Recent activities

Show all activities

OSS Rebuild information

  • Developed by

    US flagGoogle
  • Licensing

    Open Source (Apache-2.0) and Free product.
  • Written in

  • Alternatives

    15 alternatives listed
  • Supported Languages

    • English

AlternativeTo Categories

DevelopmentSecurity & Privacy

GitHub repository

  •  674 Stars
  •  41 Forks
  •  102 Open Issues
  •   Updated  
View on GitHub
OSS Rebuild was added to AlternativeTo by Paul on and this page was last updated .
No comments or reviews, maybe you want to be first?
Post comment/review

What is OSS Rebuild?

Secure open-source package ecosystems by originating, validating, and augmenting build attestations.

OSS Rebuild aims to apply reproducible build concepts at low-cost and high-scale for open-source package ecosystems.

Rebuilds are derived by analyzing the published metadata and artifacts and are evaluated against the upstream package versions. When successful, build attestations are published for the upstream artifacts, verifying the integrity of the upstream artifact and eliminating many possible sources of compromise.

We currently support the following ecosystems:

  • NPM (JavaScript/TypeScript)
  • PyPI (Python)
  • Crates.io (Rust)

While complete coverage is the aim, only the most popular packages within each ecosystem are currently rebuilt.

Official Links