<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr" -->

---
title: Google Launches OSS Rebuild to Enhance Open Source Security
description: Google launched OSS Rebuild, a security tool that automatically reconstructs open-source packages from PyPI, npm, and Crates.io repositories to generate SLSA...
canonical: https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Google Launches OSS Rebuild to Enhance Open Source Security | daily.dev
og:description: Google launched OSS Rebuild, a security tool that automatically reconstructs open-source packages from PyPI, npm, and Crates.io repositories to generate SLSA...
og:url: https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr
og:image: https://api.daily.dev/og/posts/Vjw24zqjR.png
og:image:alt: Google Launches OSS Rebuild to Enhance Open Source Security
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Launches OSS Rebuild to Enhance Open Source Security

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Google launched OSS Rebuild, a security tool that automatically reconstructs open-source packages from PyPI, npm, and Crates.io repositories to generate SLSA provenance attestations. The tool helps detect supply chain attacks by comparing rebuilt packages against published versions, identifying unauthorized code, backdoors, and build discrepancies. It supports Python, JavaScript/TypeScript, and Rust ecosystems while providing SLSA Build Level 3 provenance information for enhanced vulnerability management.

## Content

Google has introduced OSS Rebuild, an innovative project aimed at bolstering the security of widely used open-source packages. This initiative automatically reconstructs packages from major repositories such as PyPI, npm, and Crates.io, generating SLSA (Supply chain Levels for Software Artifacts) provenance attestations to ensure the integrity and trustworthiness of these components.

OSS Rebuild addresses the rising concerns of supply chain attacks by reproducing upstream artifacts and verifying them against published packages. This meticulous comparison helps identify potential compromises, including unauthorized code additions, hidden backdoors, and discrepancies in build environments. By offering this additional layer of scrutiny, Google allows enterprises to enhance their software dependency security without imposing extra burdens on package maintainers.

The tool is compatible with Python, JavaScript/TypeScript, and Rust package ecosystems, and it's capable of providing SLSA Build Level 3 provenance information. This enables organizations to integrate OSS Rebuild seamlessly into their vulnerability response workflows, granting them enhanced metadata and observability tools to track and manage vulnerabilities proactively.

By making the provenance of package builds transparent, Google empowers developers and enterprises to trust open-source software components confidently. The OSS Rebuild's capacity to identify malicious code and unsubmitted source code makes it a vital tool in the ongoing effort to safeguard the integrity of software supply chains.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#google](https://daily.dev/tags/google)

[View this post on daily.dev](https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Google Launches OSS Rebuild to Enhance Open Source Security","url":"https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr"},"datePublished":"2025-07-23T19:31:09.408Z","dateModified":"2025-07-23T19:31:28.078Z","description":"Google launched OSS Rebuild, a security tool that automatically reconstructs open-source packages from PyPI, npm, and Crates.io repositories to generate SLSA...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/776cb31af0196b8092b2107c7ca27d9d?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/776cb31af0196b8092b2107c7ca27d9d?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/google-launches-oss-rebuild-to-enhance-open-source-security-vjw24zqjr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,open-source,google","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Google Launches OSS Rebuild to Enhance Open Source Security"}]}
```

