<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past?]]></title><description><![CDATA[<p>Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past?</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/" title="In a Big Move to Linux Security, Debian Makes Reproducible Builds Mandatory">
<img src="https://itsfoss.com/content/images/2026/05/debian-reproducible-builds-banner.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/">
In a Big Move to Linux Security, Debian Makes Reproducible Builds Mandatory
</a>
</h5>
<p class="card-text line-clamp-3">Packages that can't be rebuilt byte-for-byte are now blocked from entering Debian's testing branch.</p>
</div>
<a href="https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://itsfoss.com/content/images/size/w256h256/2025/11/android-chrome-512x512.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0">It's FOSS <span class="text-secondary">(itsfoss.com)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/1f155029-cc66-499a-acbf-3228e53f3324/would-this-move-by-debian-requiring-byte-for-byte-reproducible-builds-have-caught-any-real-world-supply-chain-attacks-seen-in-the-past</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 07:46:09 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/1f155029-cc66-499a-acbf-3228e53f3324.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 18:33:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past? on Wed, 13 May 2026 19:43:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/kemotep%40mastodo.neoliber.al">@<span>kemotep</span></a></span> <span><a href="/user/dangoodin%40infosec.exchange">@<span>dangoodin</span></a></span> well, in the xz case, it was actually one of the main contributors who slipped in the attack. There is little that can be done against that.</p>]]></description><link>https://board.circlewithadot.net/post/https://fediscience.org/users/GeorgWeissenbacher/statuses/116568975641366594</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fediscience.org/users/GeorgWeissenbacher/statuses/116568975641366594</guid><dc:creator><![CDATA[georgweissenbacher@fediscience.org]]></dc:creator><pubDate>Wed, 13 May 2026 19:43:30 GMT</pubDate></item><item><title><![CDATA[Reply to Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past? on Wed, 13 May 2026 19:33:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/kemotep%40mastodo.neoliber.al">@<span>kemotep</span></a></span> <span><a href="/user/dangoodin%40infosec.exchange">@<span>dangoodin</span></a></span> it’s about being able to prove that the binary distribution matches the source code. If the source code is already tainted it won’t help.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/brown/statuses/116568935120304382</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/brown/statuses/116568935120304382</guid><dc:creator><![CDATA[brown@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 19:33:12 GMT</pubDate></item><item><title><![CDATA[Reply to Would this move by Debian, requiring byte-for-byte reproducible builds, have caught any real-world supply chain attacks seen in the past? on Wed, 13 May 2026 19:00:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/dangoodin%40infosec.exchange" rel="nofollow noopener">@<span>dangoodin</span></a></span> it would not have caught the xz attack. But is the point of reproducible builds more about consistency and reliability than security?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodo.neoliber.al/users/kemotep/statuses/116568804609913736</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodo.neoliber.al/users/kemotep/statuses/116568804609913736</guid><dc:creator><![CDATA[kemotep@mastodo.neoliber.al]]></dc:creator><pubDate>Wed, 13 May 2026 19:00:00 GMT</pubDate></item></channel></rss>