{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:25:32Z","timestamp":1783610732662,"version":"3.55.0"},"reference-count":88,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2022,11,29]],"date-time":"2022-11-29T00:00:00Z","timestamp":1669680000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,11,29]],"date-time":"2022-11-29T00:00:00Z","timestamp":1669680000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100003170","name":"Stiftelsen f\u00f6r Kunskaps- och Kompetensutveckling","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003170","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014791","name":"University of Sk\u00f6vde","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100014791","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Software Qual J"],"published-print":{"date-parts":[[2023,9]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Reproducible builds (R-Bs) are software engineering practices that reliably create bit-for-bit identical binary executable files from specified source code. R-Bs are applied in some open source software (OSS) projects and distributions to allow verification that the distributed binary has been built from the released source code. The use of R-Bs has been advocated in software maintenance and R-Bs are applied in the development of some OSS\u00a0security applications. Nonetheless, industry application of R-Bs appears limited, and we seek to understand whether awareness is low or if significant technical and business reasons prevent wider adoption. Through interviews with software practitioners and business managers, this study explores the utility of applying R-Bs in businesses in the primary and secondary software sectors and the business and technical reasons supporting their adoption. We find businesses use R-Bs in the safety-critical and security domains, and R-Bs are valuable for traceability and support collaborative software development. We also found that R-Bs are valued as engineering processes and are seen as a badge of software quality, but without a tangible value proposition. There are good engineering reasons to use R-Bs in industrial software development, and the principle of establishing correspondence between source code and binary offers opportunities for the development of further applications.<\/jats:p>","DOI":"10.1007\/s11219-022-09607-z","type":"journal-article","created":{"date-parts":[[2022,11,29]],"date-time":"2022-11-29T07:22:37Z","timestamp":1669706557000},"page":"687-719","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["On business adoption and use of reproducible builds for open and closed source software"],"prefix":"10.1007","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6215-3753","authenticated-orcid":false,"given":"Simon","family":"Butler","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonas","family":"Gamalielsson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bj\u00f6rn","family":"Lundell","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christoffer","family":"Brax","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anders","family":"Mattsson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tomas","family":"Gustavsson","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonas","family":"Feist","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bengt","family":"Kvarnstr\u00f6m","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Erik","family":"L\u00f6nroth","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,29]]},"reference":[{"key":"9607_CR1","unstructured":"ACT. (2020). Automated compliance tooling. https:\/\/automatecompliance.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR2","unstructured":"\u00c5gerfalk, P., Deverell, A., Fitzgerald, B., et\u00a0al. (2005). Assessing the role of OSS in the European secondary software sector: A voice from industry. In: Proceedings of the 1st International Conference on Open Source Software, pp 82\u201387."},{"key":"9607_CR3","unstructured":"Alpine Linux. (2020). Alpine Linux. URL https:\/\/alpinelinux.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR4","unstructured":"Apache Maven. (2022). Configuring for reproducible builds. https:\/\/maven.apache.org\/guides\/mini\/guide-reproducible-builds.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR5","unstructured":"Bazel. (2020). Bazel \u2014 a fast, scalable, multi-language and extensible build system. URL https:\/\/bazel.build\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR6","unstructured":"Bitcoin Project. (2022). Bitcoin core. URL https:\/\/bitcoin.org\/en\/bitcoin-core\/, Retrieved: 01 Jul 2022."},{"issue":"1","key":"9607_CR7","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/S0959-8022(98)00018-6","volume":"9","author":"K Braa","year":"1999","unstructured":"Braa, K., & Vidgen, R. T. (1999). Interpretation, intervention and reduction in the organizational laboratory: A framework for in-context information systems research. Accounting, Management and Information Technologies, 9(1), 25\u201347. https:\/\/doi.org\/10.1016\/S0959-8022(98)00018-6","journal-title":"Accounting, Management and Information Technologies"},{"issue":"2","key":"9607_CR8","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1191\/1478088706qp063oa","volume":"3","author":"V Braun","year":"2006","unstructured":"Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77\u2013101. https:\/\/doi.org\/10.1191\/1478088706qp063oa","journal-title":"Qualitative Research in Psychology"},{"key":"9607_CR9","unstructured":"Bressers, J. (2016). Trusting, trusting trust. http:\/\/sobersecurity.blogspot.com\/2016\/05\/trusting-trusting-trust.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR10","unstructured":"Chen, R. (2018). Why are the module timestamps in Windows 10 so nonsensical? https:\/\/devblogs.microsoft.com\/oldnewthing\/20180103-00\/?p=97705, Retrieved: 30 Jun 2020."},{"key":"9607_CR11","unstructured":"Court\u00e8s, L. (2013). Functional package management with Guix. In: Proceedings of ELS 2013 - 6th European Lisp Symposium, pp 4\u201314. https:\/\/european-lisp-symposium.org\/static\/proceedings\/2013.pdf#page=10"},{"key":"9607_CR12","doi-asserted-by":"publisher","unstructured":"Court\u00e8s, L. (2017). Code staging in GNU Guix. In: Proceedings of the 16th ACM SIGPLAN International Conference on Generative Programming: Concepts and Experiences. Association for Computing Machinery, New York, NY, USA, GPCE 2017, pp 41\u201348. https:\/\/doi.org\/10.1145\/3136040.3136045","DOI":"10.1145\/3136040.3136045"},{"key":"9607_CR13","doi-asserted-by":"publisher","unstructured":"Court\u00e8s, L., & Wurmus, R. (2015). Reproducible and user-controlled software environments in HPC with Guix. In: Euro-Par 2015: Parallel Processing Workshops. Springer International Publishing, Cham, pp 579\u2013591. https:\/\/doi.org\/10.1007\/978-3-319-27308-2_47","DOI":"10.1007\/978-3-319-27308-2_47"},{"key":"9607_CR14","unstructured":"Court\u00e8s, L. (2019). Connecting reproducible deployment to a long-term source code archive. https:\/\/guix.gnu.org\/blog\/2019\/connecting-reproducible-deployment-to-a-long-term-source-code-archive\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR15","unstructured":"Court\u00e8s, L. (2020). Guix: Unifying provisioning, deployment, and package management in the age of containers. https:\/\/fosdem.org\/2020\/schedule\/event\/guix\/, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR16","doi-asserted-by":"publisher","unstructured":"de\u00a0Carn\u00e9\u00a0de Carnavalet, X., & Mannan, M. (2014). Challenges and implications of verifiable builds for security-critical open-source software. In: Proceedings of the 30th Annual Computer Security Applications Conference. ACM, New York, NY, USA, ACSAC \u201914, pp 16\u201325. https:\/\/doi.org\/10.1145\/2664243.2664288","DOI":"10.1145\/2664243.2664288"},{"issue":"5\u20136","key":"9607_CR17","doi-asserted-by":"publisher","first-page":"577","DOI":"10.1017\/S0956796810000195","volume":"20","author":"E Dolstra","year":"2010","unstructured":"Dolstra, E., L\u00f6h, A., & Pierron, N. (2010). NixOS: A purely functional Linux distribution. Journal of Functional Programming, 20(5\u20136), 577\u2013615. https:\/\/doi.org\/10.1017\/S0956796810000195","journal-title":"Journal of Functional Programming"},{"key":"9607_CR18","unstructured":"Dong, C. (2019). Bitcoin build system security. https:\/\/www.youtube.com\/watch?v=I2iShmUTEl8, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR19","unstructured":"Edge, J. (2019). A backdoor in a popular Ruby gem. URL https:\/\/lwn.net\/Articles\/785386\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR20","unstructured":"Egts, D., & Hellekson, G. (2021). Dave & Gunnar show episode 212: Security requires thinking (his monkey, his circus). https:\/\/dgshow.org\/212, Retrieved: 01 Jul 2022."},{"issue":"2","key":"9607_CR21","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1109\/MSEC.2022.3142338","volume":"20","author":"W Enck","year":"2022","unstructured":"Enck, W., & Williams, L. (2022). Top five challenges in software supply chain security: Observations from 30 industry and government organizations. IEEE Security & Privacy, 20(2), 96\u2013100. https:\/\/doi.org\/10.1109\/MSEC.2022.3142338","journal-title":"IEEE Security & Privacy"},{"key":"9607_CR22","unstructured":"European Commission. (2021). Proposal for a regulation of the european parliament and of the council laying down harmonised rules on artificial intelligence (artificial intelligence act) and amending certain union legislative acts. https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:52021PC0206, Retrieved: 01 Jun 2022."},{"key":"9607_CR23","unstructured":"European Council. (2016). Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/ec (General Data Protection Regulation). https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj, Retrieved: 30 Jun 2021."},{"key":"9607_CR24","unstructured":"Fowler, M. (2010). ReproducibleBuild. https:\/\/martinfowler.com\/bliki\/ReproducibleBuild.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR25","unstructured":"Gallagher, R., & Greenwald, G. (2014). How the NSA plans to infect \u2018millions\u2019 of computers with malware. https:\/\/theintercept.com\/2014\/03\/12\/nsa-plans-infect-millions-computers-malware\/, Retrieved: 25 Oct 2021."},{"key":"9607_CR26","unstructured":"GCC. (2020). The C preprocessor: Section 13 environment variables. URL https:\/\/gcc.gnu.org\/onlinedocs\/cpp\/Environment-Variables.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR27","unstructured":"Geyer-Blaumeiser, L. (2019). Ensuring open source compliance using Eclipse Foundation technology. https:\/\/github.com\/Open-Source-Compliance\/Sharing-creates-value\/blob\/master\/Presentations\/2019_10_22_EclipseConEurope_EnsuringOpenSourceCompliance.pdf, Retrieved: 01 Jul 2022."},{"key":"9607_CR28","unstructured":"GNU Guix. (2019). GNU Guix \u2014 GNU\u2019s advanced distro and transactional package manager. https:\/\/guix.gnu.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR29","unstructured":"Google Cloud. (2020). Binary authorization for Borg: How Google verifies code provenance and implements code identity. https:\/\/cloud.google.com\/security\/binary-authorization-for-borg, Retrieved: 01 Jul 2022."},{"key":"9607_CR30","unstructured":"GReAT AMR. (2019). Operation shadowHammer: A high profile supply chain attack. https:\/\/securelist.com\/operation-shadowhammer-a-high-profile-supply-chain-attack\/90380\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR31","unstructured":"Greenberg, A. (2017). Software has a serious supply-chain security problem. https:\/\/www.wired.com\/story\/ccleaner-malware-supply-chain-software-security\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR32","unstructured":"Greenberg, A. (2018). A mysterious hacker group is on a supply chain hijacking spree. URL https:\/\/www.wired.com\/story\/barium-supply-chain-hackers\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR33","unstructured":"Guix-HPC. (2020). Guix-HPC reproducible software deployment for high-performance computing. https:\/\/hpc.guix.info\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR34","unstructured":"Hemel, A. (2020). Docker containers for legal professionals. URL https:\/\/www.linuxfoundation.org\/wp-content\/uploads\/Docker-Containers-for-Legal-Professionals-Whitepaper_042420.pdf, Retrieved: 01 Jul 2022."},{"key":"9607_CR35","unstructured":"Hurst, R. (2021). Verifiable design in modern systems. URL https:\/\/security.googleblog.com\/2021\/07\/verifiable-design-in-modern-systems.html, Retrieved: 29 Jun 2022."},{"key":"9607_CR36","doi-asserted-by":"publisher","unstructured":"Ivankovi\u0107, M., Petrovi\u0107, G., Just, R., et\u00a0al. (2019). Code coverage at google. In: Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. Association for Computing Machinery, New York, NY, USA, ESEC\/FSE 2019, pp 955\u2013963. https:\/\/doi.org\/10.1145\/3338906.3340459","DOI":"10.1145\/3338906.3340459"},{"key":"9607_CR37","unstructured":"Jacomet, L. (2020). Protecting yourself against attacks through the build. URL https:\/\/jfokus.se\/jfokus20\/talks\/302, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR38","unstructured":"Johnson, E. (2020). H.R.6216 - national artificial intelligence initiative act of 2020. URL https:\/\/www.congress.gov\/bill\/116th-congress\/house-bill\/6216, Retrieved: 01 Jun 2022."},{"key":"9607_CR39","unstructured":"Kang, Y., Chen, Z., & Wei, R. (2015). XcodeGhost S: A new breed hits the US. https:\/\/www.fireeye.com\/blog\/threat-research\/2015\/11\/xcodeghost_s_a_new.html, Retrieved: 25 Oct 2021."},{"key":"9607_CR40","unstructured":"Kuhn, B. M., McAffer, J., Sills, M., et\u00a0al. (2020). Does careful inventory of licensing bill of materials have real impact on FOSS license compliance? URL https:\/\/fosdem.org\/2020\/schedule\/event\/debate_license_compliance\/, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR41","unstructured":"Lamb, C., & Luo, X. (2017) SOURCE_DATE_EPOCH specification. https:\/\/reproducible-builds.org\/specs\/source-date-epoch\/, Retrieved: 01 Jul 2022."},{"issue":"2","key":"9607_CR42","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1109\/MS.2021.3073045","volume":"39","author":"C Lamb","year":"2021","unstructured":"Lamb, C., & Zacchiroli, S. (2021). Reproducible builds: Increasing the integrity of software supply chains. IEEE Software, 39(2), 62\u201370. https:\/\/doi.org\/10.1109\/MS.2021.3073045","journal-title":"IEEE Software"},{"key":"9607_CR43","unstructured":"Levsen, H. (2016). Beyond reproducible builds. making the whole free software ecosystem reproducible and then .... https:\/\/archive.fosdem.org\/2016\/schedule\/event\/reproducible_ecosystem\/, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR44","unstructured":"Levsen, H., et\u00a0al. (2019). Overview of various statistics about reproducible builds. URL https:\/\/tests.reproducible-builds.org\/debian\/reproducible.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR45","unstructured":"Linderud, M. (2019). Reproducible builds: Break a log, good things come in trees. Master\u2019s thesis, University of Bergen, http:\/\/bora.uib.no\/handle\/1956\/20411"},{"key":"9607_CR46","doi-asserted-by":"publisher","unstructured":"Lundell, B., & Gamalielsson, J. (2017). Collaborative research involving small companies: Experiences from co-production of knowledge for research and practice through use of an action case approach. In: 2017 IEEE\/ACM 4th International Workshop on Software Engineering Research and Industrial Practice (SER IP), pp 24\u201330. https:\/\/doi.org\/10.1109\/SER-IP.2017.4","DOI":"10.1109\/SER-IP.2017.4"},{"key":"9607_CR47","doi-asserted-by":"publisher","unstructured":"McDonald, N., Schoenebeck, S., & Forte, A. (2019). Reliability and inter-rater reliability in qualitative research: Norms and guidelines for CSCW and HCI practice. Proceedings of the ACM on Human-Computer Interaction 3(CSCW). https:\/\/doi.org\/10.1145\/3359174","DOI":"10.1145\/3359174"},{"key":"9607_CR48","doi-asserted-by":"publisher","unstructured":"Navarro\u00a0Leija, O.S., Shiptoski, K., Scott, R.G., et\u00a0al. (2020). Reproducible containers. In: Proceedings of the Twenty-Fifth International Conference on Architectural Support for Programming Languages and Operating Systems(ASPLOS \u201920). ACM, New York, NY, USA. https:\/\/doi.org\/10.1145\/3373376.3378519","DOI":"10.1145\/3373376.3378519"},{"key":"9607_CR49","unstructured":"Nesbitt, A., & Pounds, A. (2019). The manifest \u2013 Episode 14: Debian and reproducible builds with Chris Lamb. https:\/\/manifest.fm\/14, [Audio] Retrieved: 01 Jul 2021."},{"key":"9607_CR50","unstructured":"NixOS. (2020). NixOS Linux. https:\/\/nixos.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR51","doi-asserted-by":"publisher","unstructured":"Ohm, M., Plate, H., Sykosch, A., et\u00a0al. (2020). Backstabber\u2019s knife collection: A review of open source software supply chain attacks. In: Proceedings of The 17th Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA). Springer International Publishing, Cham, LNCS, pp 23\u201343. https:\/\/doi.org\/10.1007\/978-3-030-52683-2_2","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"9607_CR52","unstructured":"Peachey, K. (2022). Post office scandal: What the horizon saga is all about. URL https:\/\/www.bbc.com\/news\/business-56718036, Retrieved: 30 Jun 2022."},{"key":"9607_CR53","unstructured":"Perry, M. (2013). Reproducible builds: Part one: Moving beyond single points of failure for software distribution. URL https:\/\/blog.torproject.org\/deterministic-builds-part-one-cyberwar-and-global-compromise, Retrieved: 01 Jul 2022."},{"key":"9607_CR54","unstructured":"Perry, M., Schoen, S., & Steiner, H. (2014). Reproducible builds: Moving beyond single points of failure for software distribution. https:\/\/media.ccc.de\/v\/31c3_-_6240_-_en_-_saal_g_-_201412271400_-_reproducible_builds_-_mike_perry_-_seth_schoen_-_hans_steiner, [Video] Retrieved: 01 Jul 2022."},{"key":"9607_CR55","unstructured":"Piotrowski, M. (2018). ReproducibleBuilds. https:\/\/wiki.freebsd.org\/ReproducibleBuilds, Retrieved: 01 Jul 2022."},{"key":"9607_CR56","unstructured":"Porup, J. M. (2016). How to make Linux more trustworthy. https:\/\/arstechnica.com\/information-technology\/2016\/12\/how-to-make-linux-more-trustworthy\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR57","unstructured":"Pothon, F., & Ochem, Q. (2017). AdaCore Technologies for DO-178C\/ED-12C. AdaCore. http:\/\/www.adacore.com\/gnatpro-safety-critical\/avionics\/do178c\/"},{"issue":"7","key":"9607_CR58","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1145\/2854146","volume":"59","author":"R Potvin","year":"2016","unstructured":"Potvin, R., & Levenberg, J. (2016). Why Google stores billions of lines of code in a single repository. Commun ACM, 59(7), 78\u201387. https:\/\/doi.org\/10.1145\/2854146","journal-title":"Commun ACM"},{"key":"9607_CR59","unstructured":"Ramakrishna, S. (2021). New findings from our investigation of sunburst. https:\/\/orangematter.solarwinds.com\/2021\/01\/11\/new-findings-from-our-investigation-of-sunburst\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR60","doi-asserted-by":"publisher","unstructured":"Ren, Z., Jiang, H., Xuan, J., et\u00a0al. (2018). Automated localization for unreproducible builds. In: Proceedings of the 40th International Conference on Software Engineering, ICSE 2018. ACM, New York, NY, USA, pp 71\u201381. https:\/\/doi.org\/10.1145\/3180155.3180224","DOI":"10.1145\/3180155.3180224"},{"key":"9607_CR61","doi-asserted-by":"publisher","unstructured":"Ren, Z., Liu, C., Xiao, X., et\u00a0al. (2019). Root cause localization for unreproducible builds via causality analysis over system call tracing. In: Proceedings of the 34th IEEE\/ACM International Conference on Automated Software Engineering. IEEE Press, ASE \u201919, p 527-538. https:\/\/doi.org\/10.1109\/ASE.2019.00056","DOI":"10.1109\/ASE.2019.00056"},{"key":"9607_CR62","doi-asserted-by":"publisher","unstructured":"Ren, Z., Sun, S., Xuan, J., et\u00a0al. (2022). Automated patching for unreproducible builds. In: 2022 IEEE\/ACM 44th International Conference on Software Engineering (ICSE), pp 200\u2013211. https:\/\/doi.org\/10.1145\/3510003.3510102","DOI":"10.1145\/3510003.3510102"},{"key":"9607_CR63","unstructured":"Reproducible Builds. (2022). reprotest. https:\/\/salsa.debian.org\/reproducible-builds\/reprotest, Retrieved: 01 Jul 2022."},{"key":"9607_CR64","unstructured":"Reproducible Builds Project. (2019a). Definitions. https:\/\/reproducible-builds.org\/docs\/definition, Retrieved: 25 Oct 2021."},{"key":"9607_CR65","unstructured":"Reproducible Builds Project. (2019b). Reproducible builds \u2013 a set of software development practices that create an independently verifiable path from source to binary code. https:\/\/reproducible-builds.org\/, Retrieved: 25 Oct 2021."},{"key":"9607_CR66","unstructured":"Reproducible Builds Project. (2022). diffoscope: In-depth comparison of files, archives, and directories. https:\/\/diffoscope.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR67","doi-asserted-by":"publisher","unstructured":"Riehle, D., Harutyunyan, N. (2019). Open-source license compliance in software supply chains. In: Fitzgerald B, Mockus A, Zhou M (eds) Towards Engineering Free\/Libre Open Source Software (FLOSS) Ecosystems for Impact and Sustainability: Communications of NII Shonan Meetings. Communications of NII Shonan Meetings, Springer Singapore, Singapore, chap\u00a05, p 83\u201395. https:\/\/doi.org\/10.1007\/978-981-13-7099-1_5","DOI":"10.1007\/978-981-13-7099-1_5"},{"issue":"4","key":"9607_CR68","doi-asserted-by":"publisher","first-page":"2930","DOI":"10.1007\/s10664-020-09828-5","volume":"25","author":"G Rousseau","year":"2020","unstructured":"Rousseau, G., Di Cosmo, R., & Zacchiroli, S. (2020). Software provenance tracking at the scale of public source code. Empirical Software Engineering, 25(4), 2930\u20132959. https:\/\/doi.org\/10.1007\/s10664-020-09828-5","journal-title":"Empirical Software Engineering"},{"key":"9607_CR69","unstructured":"RTCA. (2011). DO-178C \u2013 Software Considerations in Airborne Systems and Equipment Certification. RTCA Incorporated."},{"key":"9607_CR70","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1038\/s42256-019-0048-x","volume":"1","author":"C Rudin","year":"2019","unstructured":"Rudin, C. (2019). Stop explaining black box machine learning models for high stakes decisions and use interpretable models instead. Nature Machine Intelligence, 1, 206\u2013215. https:\/\/doi.org\/10.1038\/s42256-019-0048-x","journal-title":"Nature Machine Intelligence"},{"key":"9607_CR71","unstructured":"Secure Systems Lab. (2022). in-toto: A framework to secure the integrity of software supply chains. https:\/\/in-toto.io\/, Retrieved: 01 Jul 2022."},{"issue":"1","key":"9607_CR72","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1353-4858(16)30006-X","volume":"2016","author":"M Shaulov","year":"2016","unstructured":"Shaulov, M. (2016). Bridging mobile security gaps. Network Security, 2016(1), 5\u20138. https:\/\/doi.org\/10.1016\/S1353-4858(16)30006-X","journal-title":"Network Security"},{"key":"9607_CR73","doi-asserted-by":"publisher","unstructured":"Shi, Y., Wen, M., Cogo, F. R., et\u00a0al. (2021). An experience report on producing verifiable builds for large-scale commercial systems. IEEE Transactions on Software Engineering pp 1. https:\/\/doi.org\/10.1109\/TSE.2021.3092692, (Early access)","DOI":"10.1109\/TSE.2021.3092692"},{"key":"9607_CR74","unstructured":"Smith, J. K. (2011). Security incident on Fedora infrastructure on 23 jan 2011. https:\/\/lists.fedoraproject.org\/pipermail\/announce\/2011-January\/002911.html, Retrieved: 01 Jul 2022."},{"key":"9607_CR75","unstructured":"Software Heritage. (2019). Software Heritage. https:\/\/www.softwareheritage.org\/, Retrieved: 25 Oct 2021."},{"key":"9607_CR76","unstructured":"SPDX Workgroup. (2021). Software Package Data Exchange. https:\/\/spdx.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR77","doi-asserted-by":"publisher","unstructured":"Tapas, N., Longo, F., Merlino, G., et\u00a0al. (2019). Transparent, provenance-assured, and secure software-as-a-service. In: 2019 IEEE 18th International Symposium on Network Computing and Applications (NCA), pp 1\u20138. https:\/\/doi.org\/10.1109\/NCA.2019.8935014","DOI":"10.1109\/NCA.2019.8935014"},{"issue":"8","key":"9607_CR78","doi-asserted-by":"publisher","first-page":"761","DOI":"10.1145\/358198.358210","volume":"27","author":"K Thompson","year":"1984","unstructured":"Thompson, K. (1984). Reflections on trusting trust. Communications of the ACM, 27(8), 761\u2013763. https:\/\/doi.org\/10.1145\/358198.358210","journal-title":"Communications of the ACM"},{"key":"9607_CR79","unstructured":"Tor Project. (2022). Tor project: Anonymity online. https:\/\/www.torproject.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR80","unstructured":"Torres-Arias, S., Afzali, H., Karthik\u00a0Kuppusamy, T., et\u00a0al. (2019). in-toto: Providing farm-to-table guarantees for bits and bytes. In: 28th USENIX Security Symposium, USENIX Security 2019. USENIX Association, pp 1393\u20131410. https:\/\/www.usenix.org\/system\/files\/sec19-torres-arias.pdf"},{"key":"9607_CR81","doi-asserted-by":"publisher","unstructured":"van\u00a0der Burg, S., Dolstra, E., McIntosh, S., et\u00a0al. (2014). Tracing software build processes to uncover license compliance inconsistencies. In: Proceedings of the 29th ACM\/IEEE International Conference on Automated Software Engineering. Association for Computing Machinery, New York, NY, USA, ASE \u201814, pp 731\u2013742. https:\/\/doi.org\/10.1145\/2642937.2643013","DOI":"10.1145\/2642937.2643013"},{"key":"9607_CR82","unstructured":"Vinet, J., & Griffin, A. (2022) Arch Linux. https:\/\/www.archlinux.org\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR83","doi-asserted-by":"publisher","unstructured":"Wang, J., Kuo, T., Li, L., et\u00a0al. (2020). Assessing and restoring reproducibility of Jupyter notebooks. In: Proceedings of the 35th IEEE\/ACM International Conference on Automated Software Engineering. Association for Computing Machinery, New York, NY, USA, ASE \u201920, pp 138\u2013149. https:\/\/doi.org\/10.1145\/3324884.3416585","DOI":"10.1145\/3324884.3416585"},{"key":"9607_CR84","doi-asserted-by":"publisher","unstructured":"Wheeler, D. A. (2005). Countering trusting trust through diverse double-compiling. In: 21st Annual Computer Security Applications Conference (ACSAC\u201905), pp 13\u201348. https:\/\/doi.org\/10.1109\/CSAC.2005.17","DOI":"10.1109\/CSAC.2005.17"},{"key":"9607_CR85","unstructured":"Wheeler, D. A. (2009). Fully countering trusting trust through diverse double-compiling. PhD thesis, George Mason University"},{"key":"9607_CR86","unstructured":"Xiao, C. (2015). More details on the XcodeGhost malware and affected iOS apps. https:\/\/unit42.paloaltonetworks.com\/more-details-on-the-xcodeghost-malware-and-affected-ios-apps\/, Retrieved: 01 Jul 2022."},{"key":"9607_CR87","unstructured":"Yocto Project. (2021) Reproducible builds. https:\/\/wiki.yoctoproject.org\/wiki\/Reproducible_Builds, Retrieved: 01 Jul 2022."},{"key":"9607_CR88","doi-asserted-by":"crossref","unstructured":"Zerouali, A., Mens, T., Robles, G., et\u00a0al (2019) On the relation between outdated Docker containers, severity vulnerabilities, and bugs. In: 2019 IEEE 26th International Conference on Software Analysis, Evolution and Reengineering (SANER), pp 491\u2013501.","DOI":"10.1109\/SANER.2019.8668013"}],"updated-by":[{"DOI":"10.1007\/s11219-024-09664-6","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2024,3,4]],"date-time":"2024-03-04T00:00:00Z","timestamp":1709510400000}}],"container-title":["Software Quality Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-022-09607-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11219-022-09607-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-022-09607-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,4]],"date-time":"2024-03-04T13:22:22Z","timestamp":1709558542000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11219-022-09607-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,29]]},"references-count":88,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,9]]}},"alternative-id":["9607"],"URL":"https:\/\/doi.org\/10.1007\/s11219-022-09607-z","relation":{"correction":[{"id-type":"doi","id":"10.1007\/s11219-024-09664-6","asserted-by":"object"}]},"ISSN":["0963-9314","1573-1367"],"issn-type":[{"value":"0963-9314","type":"print"},{"value":"1573-1367","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,29]]},"assertion":[{"value":"10 October 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 November 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 March 2024","order":3,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Correction","order":4,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"A Correction to this paper has been published:","order":5,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"https:\/\/doi.org\/10.1007\/s11219-024-09664-6","URL":"https:\/\/doi.org\/10.1007\/s11219-024-09664-6","order":6,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}