It's like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security
Marcel Fourné, Dominik Wermke, William Enck, Sascha Fahl, Yasemin Acar
Abstract
The 2020 Solarwinds attack was a tipping point that caused a heightened awareness about the security of the software supply chain and in particular the large amount of trust placed in build systems. Reproducible Builds (R-Bs) provide a strong foundation to build defenses for arbitrary attacks against build systems by ensuring that given the same source code, build environment, and build instructions, bitwiseidentical artifacts are created. Unfortunately, much of the software industry believes R-Bs are too far out of reach for most projects. The goal of this paper is to help identify a path for R-Bs to become a commonplace property.
To this end, we conducted a series of 24 semi-structured expert interviews with participants from the Reproducible-Builds.org project, finding that self-effective work by highly motivated developers and collaborative communication with upstream projects are key contributors to R-Bs. We identified a range of motivations that can encourage open source developers to strive for R-Bs, including indicators of quality, security benefits, and more efficient caching of artifacts. We also identify experiences that help and hinder adoption, which often revolves around communication with upstream projects. We conclude with recommendations on how to better integrate R-Bs with the efforts of the open source and free software community.
RQ1: "What are motivations for, and common themes around, adopting reproducible builds in projects?" We are interested in our participants' motivations around striving for reproducible builds in their projects, specifically in the case of complex, community-or industry-driven projects, that likely necessitate a complex, interconnected system of motivations and drivers. We are also interested if some of the motivations involve security, and what specific threat models are applied. RQ2: "What experiences and challenges did projects encounter in the context of reproducible builds?" Most projects were not created with reproducibility in mind. We are interested in what experiences were made, and challenges encountered, on the way towards reproducibility, both by contributors of the project as well as with outside entities such as customers or upstream dependencies. This research question aims at the personal experiences of R-B developers. RQ3: "What are commonly encountered obstacles and facilitators in projects' efforts towards reproducibility?" Some projects stall in their efforts toward reproducibility, while others succeed. We are interested in what facilitators and obstacles our participants encountered during their efforts, how they approached them, and what they would recommend for other projects aiming to become reproducible. This research question aims at external factors encountered by R-Bs developers.
By answering these questions, we hope to guide future industry and academic efforts that target both the technical and human aspects of R-Bs. In this paper, we report the results of a semi-structured interview study with 24 prominent and public members of the R-Bs effort. All participants were experienced developers (5+ years) with R-Bs experience, who could give deep insights into their thought and development processes, and deeply discuss and reflect on the topic. Based on these interviews, we offer the following key insights.
• Open Source developers are self-motivated to work on software infrastructure. They see themselves as users as well as developers and want to build better software even without external requests.
• The Snowden revelations and SolarWinds incident heightened the security awareness. While some people were interested in R-Bs before, their number grew significantly after those two public events.
• Caching matters most to businesses. R-Bs allow for efficient caching of artifacts, which was mentioned as the most important aspect for businesses. While we specifically choose to interview experts with many invested years in R-Bs for their experience and insights, we also want to highlight that our expert participants are likely positively biased regarding the potential for R-Bs becoming widespread. While this may be substantiated by growing numbers of developers on the R-Bs mailing list as well as growing parts of operating systems being tested as built reproducibly, our sample is still biased towards R-B enthusiasts [18].
The remainder of this paper proceeds as follows. Sec-
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Closing the Chain: How to reduce your risk of being SolarWinds, Log4j, or XZ UtilsSivana Hamer, Jacob Bowen, Md Nazmul Haque, Robert Hines et al.ICSE 2026 · 5 citations
- Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution EnvironmentsDaniel Hugenroth, Mario Lins, René Mayrhofer, Alastair R. BeresfordCCS 2025 · 1 citation
- An Empirical Study on Reproducible Packaging in Open-Source EcosystemsGiacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl et al.ICSE 2025 · 1 citation
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply ChainDominik Wermke, Jan H. Klemmer, Noah Wöhler, Juliane Schmüser et al.S&P 2023
Builds on19
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified BuildsKirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly et al.USENIX Security 2017 · 144 citations
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola et al.USENIX Security 2019 · 98 citations
- "They're not that hard to mitigate": What Cryptographic Library Developers Think About Timing AttacksJan Jancar, Marcel Fourné, Daniel De Almeida Braga, Mohamed Sabt et al.S&P 2022 · 61 citations
Related papers
- Everyone for Themselves? A Qualitative Study about Individual Security Setups of Open Source Software ContributorsSabrina Amft, Sandra Höltervennhoff, Rebecca Panskus, Karola Marky et al.S&P 2024 · 21 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Committed to Trust: A Qualitative Study on Security & Trust in Open Source Software ProjectsDominik Wermke, Noah Wöhler, Jan H. Klemmer, Marcel Fourné et al.S&P 2022 · 54 citations
- AROMA: Automatic Reproduction of Maven ArtifactsMehdi Keshani, Tudor-Gabriel Velican, Gideon Bot, Sebastian ProkschFSE 2024 · 9 citations
- 'They don't care about this': A Systematic Study of TEE Build Reproducibility in the WildAnnika Wilde, Marco Gutfleisch, Felix Reichmann, Anirban Chakraborty et al.CCS 2026
