Verify a reproducible build by independently rebuilding an artifact and comparing digests

domain: reproducible-builds.org · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Obtain the official build artifact and its published digest from the upstream release
  2. Set up an independent build environment that matches the declared build toolchain, OS, and configuration as closely as possible
  3. Run the build using the same source commit and build instructions, ensuring timestamps and environment variables that affect output are neutralized
  4. Compute the digest of the locally produced artifact and compare it to the published digest
  5. If digests differ, use diffoscope to compare the two artifacts and identify the source of non-determinism
  6. Report reproducibility status and any identified non-determinism issues to the upstream project

Known gotchas

Related routes

Verify SLSA build provenance for a container image using slsa-verifier and enforce source and builder constraints
security/compliance · 5 steps · unrated
Generate a SLSA provenance attestation for a build artifact using slsa-github-generator in GitHub Actions and verify it with slsa-verifier
slsa.dev · 6 steps · unrated
Generate and verify an in-toto attestation with a SLSA provenance predicate for a build artifact
security/compliance · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans