CYBER DELTA FORCESearch

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts.

CDF News DeskGoogle Security Blog5 Aug 2025, 3:10 am
Image courtesy of Google Security Blog. Original report
CDF REPORT

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrate into their existing vulnerability management workflows.

Each incident erodes trust in open ecosystems, creating hesitation among both contributors and consumers.

With an estimated value exceeding $12 trillion , open source software has never been more integral to the global economy. The security community has responded with initiatives like OpenSSF Scorecard , pypi's Trusted Publishers , and npm's native SLSA support .

What changed

From critical infrastructure to everyday applications, OSS components now account for 77% of modern applications.

Yet this very ubiquity makes open source an attractive target: Recent high-profile supply chain attacks have demonstrated sophisticated methods for compromising widely-used packages.

Who is affected

Each incident erodes trust in open ecosystems, creating hesitation among both contributors and consumers.

How organizations are responding

With an estimated value exceeding $12 trillion , open source software has never been more integral to the global economy.

The security community has responded with initiatives like OpenSSF Scorecard , pypi's Trusted Publishers , and npm's native SLSA support .

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Suspected Black Axe gang leaders face cybercrime charges in the USBleepingComputer · 15 Sept 2026, 3:20 pmMicrosoft confirms KB5002914 Excel update breaks copy and pasteBleepingComputer · 15 Sept 2026, 2:10 pmMicrosoft releases emergency Windows updates to fix RDS failuresBleepingComputer · 15 Sept 2026, 2:22 amMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaThe Record · 15 Sept 2026, 1:10 am