With every additional rebuilder who can independently attest for construct outcomes and publish corresponding in-toto metadata, users could be extra confident that they're installing non-compromised packages. However, the issue is that it may be tough to identify a natural playground or a serious site if there are lots of impersonating websites. While both claims are valid, using in-toto compliant metadata to communicate build results would make it very simple to extend verification up the supply chain. As the in-toto team looks for ways to save the whole software supply chain, sturdy particular person hyperlinks – comparable to these reproducible builds can guarantee – will likely be wanted to assist these efforts.

When all the hyperlink metadata has been collected and the provision chain has been correctly defined, the supply chain format and all of the hyperlinks can be shipped, together with the delivered product, to the top consumer for verification. It also provides coverage language to continuously link the materials and merchandise of all activities, from writing the source code, over to high-quality assurance, until constructing and packaging the binaries. The overall group response to that concern appeared to be that such a priority is not in the scope of the Reproducible Builds project. Furthermore, it’s much less problematic because source code is less complicated to audit than binaries. Even when a quorum of rebuilders agreed on an appropriate outcome, they could have all constructed with the identical compromised supply code.

This is a project that allows operating In-Toto verifications inside a Linux container.