-
Abstract: Software supply chain attacks from SolarWinds and XZ Utils to compromised build pipelines have made it critical to verify that software binaries are trustworthy. A natural defense is to independently rebuild open-source projects and compare the resulting binaries, an approach now taken by industry initiatives such as Google's Assured Open Source Software and Oracle's…