MyNixOS website logo
Description

Securing open-source package ecosystems by originating, validating, and augmenting build attestations.

OSS Rebuild aims to apply reproducible build concepts at low-cost and high-scale for open-source package ecosystems.

Rebuilds are derived by analyzing the published metadata and artifacts and are evaluated against the upstream package versions. When successful, build attestations are published for the upstream artifacts, verifying the integrity of the upstream artifact and eliminating many possible sources of compromise.

oss-rebuild CLI tool provides access to OSS Rebuild data.

proxy is a transparent HTTP(S) proxy that intercepts and records network activity. It's primarily used within OSS Rebuild to monitor network interactions during the build process, helping to passively enumerate remote dependencies and to identify suspect build behavior.

stabilize is a command-line tool that removes non-deterministic metadata from software packages to facilitate functional comparison of artifacts.

timewarp is a registry-fronting HTTP service that filters returned content by time. This tool allows you to transparently adjust the data returned to package manager clients to reflect the state of a registry at a given point in time (especially useful for reproducing prior builds).

Metadata

Version

0-unstable-2025-07-22

License

Maintainers (1)

Platforms (28)

    Darwin
    FreeBSD
    Linux
    WASI
Show all
  • aarch64-darwin
  • aarch64-freebsd
  • aarch64-linux
  • armv5tel-linux
  • armv6l-linux
  • armv7a-linux
  • armv7l-linux
  • i686-freebsd
  • i686-linux
  • loongarch64-linux
  • m68k-linux
  • microblaze-linux
  • microblazeel-linux
  • mips-linux
  • mips64-linux
  • mips64el-linux
  • mipsel-linux
  • powerpc64-linux
  • powerpc64le-linux
  • riscv32-linux
  • riscv64-linux
  • s390-linux
  • s390x-linux
  • wasm32-wasi
  • wasm64-wasi
  • x86_64-darwin
  • x86_64-freebsd
  • x86_64-linux