{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T11:01:40Z","timestamp":1785495700699,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":12,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T00:00:00Z","timestamp":1776038400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3793302.3793328","type":"proceedings-article","created":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T10:42:54Z","timestamp":1785494574000},"page":"697-701","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["LILA: Decentralized Build Reproducibility Monitoring for the Functional Package Management Model"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9845-6300","authenticated-orcid":false,"given":"Julien","family":"Malka","sequence":"first","affiliation":[{"name":"Polytechnic Institute of Paris, Palaiseau, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5216-4485","authenticated-orcid":false,"given":"Arnout","family":"Engelen","sequence":"additional","affiliation":[{"name":"Unaffiliated, Deventer, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,31]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"2025. Reproducible Builds \u2014 a set of software development practices that create an independently-verifiable path from source to binary code. https:\/\/reproducible-builds.org\/"},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE55347.2025.00136"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","unstructured":"Ludovic Court\u00e8s. 2013. Functional Package Management with Guix. 10.48550\/arXiv.1305.4584arXiv:https:\/\/arXiv.org\/abs\/1305.4584 [cs].","DOI":"10.48550\/arXiv.1305.4584"},{"key":"e_1_3_3_2_5_2","unstructured":"Eelco Dolstra. 2006. The purely functional software deployment model. Ph.\u00a0D. Dissertation. s.n. S.l.OCLC: 71702886."},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179320"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"publisher","unstructured":"Chris Lamb and Stefano Zacchiroli. 2022. Reproducible Builds: Increasing the Integrity of Software Supply Chains. IEEE Software 39 2 (March 2022) 62\u201370. 10.1109\/MS.2021.3073045Conference Name: IEEE Software.","DOI":"10.1109\/MS.2021.3073045"},{"key":"e_1_3_3_2_8_2","unstructured":"Julien Malka. 2026. How Reproducible Builds Could Have Detected the XZ Supply-Chain Attack for the Benefit of All. (2026). https:\/\/hal.science\/hal-05326226"},{"key":"e_1_3_3_2_9_2","volume-title":"Lila, Nix hash collection software, to aggregate build reports from several builders","author":"Malka Julien","year":"2025","unstructured":"Julien Malka and Arnout Engelen. 2025. Lila, Nix hash collection software, to aggregate build reports from several builders. https:\/\/github.com\/nix-community\/Lila"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3639476.3639767"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR66628.2025.00115"},{"key":"e_1_3_3_2_12_2","unstructured":"The rebuilderd contributors. 2025. rebuilderd independent verification of binary packages - Reproducible Builds. https:\/\/github.com\/kpcyrd\/rebuilderd original-date: 2019-12-12T19:19:37Z."},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","unstructured":"Aman Sharma Benoit Baudry and Martin Monperrus. 2026. Causes and Canonicalization of Unreproducible Builds in Java. IEEE Transactions on Software Engineering 52 1 (2026) 54\u201369. 10.1109\/TSE.2025.3627891","DOI":"10.1109\/TSE.2025.3627891"}],"event":{"name":"MSR '26: 23rd International Conference on Mining Software Repositories","location":"Rio de Janeiro Brazil","acronym":"MSR '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 23rd International Conference on Mining Software Repositories"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3793302.3793328","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T10:47:39Z","timestamp":1785494859000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3793302.3793328"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,13]]},"references-count":12,"alternative-id":["10.1145\/3793302.3793328","10.1145\/3793302"],"URL":"https:\/\/doi.org\/10.1145\/3793302.3793328","relation":{},"subject":[],"published":{"date-parts":[[2026,4,13]]},"assertion":[{"value":"2026-07-31","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}