Introducing OSS Rebuild: Open Source, Rebuilt to Last
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts.

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrate into their existing vulnerability management workflows.
Each incident erodes trust in open ecosystems, creating hesitation among both contributors and consumers.
With an estimated value exceeding $12 trillion , open source software has never been more integral to the global economy. The security community has responded with initiatives like OpenSSF Scorecard , pypi's Trusted Publishers , and npm's native SLSA support .
What changed
From critical infrastructure to everyday applications, OSS components now account for 77% of modern applications.
Yet this very ubiquity makes open source an attractive target: Recent high-profile supply chain attacks have demonstrated sophisticated methods for compromising widely-used packages.
Who is affected
Each incident erodes trust in open ecosystems, creating hesitation among both contributors and consumers.
How organizations are responding
With an estimated value exceeding $12 trillion , open source software has never been more integral to the global economy.
The security community has responded with initiatives like OpenSSF Scorecard , pypi's Trusted Publishers , and npm's native SLSA support .
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
What remains unknown
The available reporting does not establish whether the issue is being actively exploited in the wild.
The available reporting does not establish who is behind the activity, if an attacker is involved.