An Empirical Study on Reproducible Packaging in Open-Source Ecosystems
Giacomo Benedetti, Oreofe Solarin, Courtney Miller, Greg Tystahl, William Enck, Christian Kästner, Alexandros Kapravelos, Alessio Merlo, Luca Verderame
Abstract
The integrity of software builds is fundamental to the security of the software supply chain. While Thompson first raised the potential for attacks on build infrastructure in 1984, limited attention has been given to build integrity in the past 40 years, enabling recent attacks on SolarWinds, event-stream, and xz. The best-known defense against build system attacks is creating reproducible builds; however, achieving them can be complex for both technical and social reasons and thus is often viewed as impractical to obtain. In this paper, we analyze reproducibility of builds in a novel context: reusable components distributed as packages in six popular software ecosystems (npm, Maven, PyPI, Go, RubyGems, and Cargo). Our quantitative study on a representative sample of 4000 packages in each ecosystem raises concerns: Rates of reproducible builds vary widely between ecosystems, with some ecosystems having all packages reproducible whereas others have reproducibility issues in nearly every package. However, upon deeper investigation, we identified that with relatively straightforward infrastructure configuration and patching of build tools, we can achieve very high rates of reproducible builds in all studied ecosystems. We conclude that if the ecosystems adopt our suggestions, the build process of published packages can be independently confirmed for nearly all packages without individual developer actions, and doing so will prevent significant future software supply chain attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bbe520d7-e1ba-4975-9927-e8dcdccfeea5Cited by top-tier papers1
Ask how each one uses itBuilds on7
- CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified BuildsKirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly et al.USENIX Security 2017 · 144 citations
- A Qualitative Study of Dependency Management and Its Security ImplicationsIvan Pashchenko, Duc-Ly Vu, Fabio MassacciCCS 2020 · 84 citations
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate et al.FSE 2021 · 53 citations
- Automated Patching for Unreproducible BuildsZhilei Ren, Shiwei Sun, Jifeng Xuan, Xiaochen Li et al.ICSE 2022 · 18 citations
- AROMA: Automatic Reproduction of Maven ArtifactsMehdi Keshani, Tudor-Gabriel Velican, Gideon Bot, Sebastian ProkschFSE 2024 · 9 citations
Related papers
- It's like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain SecurityMarcel Fourné, Dominik Wermke, William Enck, Sascha Fahl et al.S&P 2023
- Investigating Package Related Security Threats in Software RegistriesYacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu et al.S&P 2023
- Fighting Supply Chain Attacks with Effect SystemsMagnus Madsen, Andreas Stenbæk Larsen, Jakob Schneider Villumsen, Aslan AskarovOOPSLA 2026
- An Empirical Study of Observability Limits in Advanced Software Supply Chain AttacksZhuoran Tan, Wenbo Guo, Jiewen Luo, Taylor Brierley et al.CCS 2026 · 3 citations
- ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at ScaleWenxin Jiang, Berk Çakar, Mikola Lysenko, James C DavisICSE 2026 · 2 citations
