The term "Reproducible Builds" refers to making sure the build process for various artifacts is so deterministic that building the same sources twice results in a bit-by-bit identical artifact. You can read more about it on https://reproducible-builds.org/.
One of the advantages of Reproducible Builds is that, when those two builds happen on independently-managed infrastructure, validating that both environments produce the same bit-by-bit artifact improves the confidence that no backdoor or other malware was injected into the artifact due to a compromise of the infrastructure.
It is good practice for all artifacts released by the ASF to be reproducible. For projects that want to build and sign artifacts on CI, Reproducible Builds are required. This means:
See below for any ecosystem-specific notes that could be helpful for other projects to make their builds reproducible. If you have additional input to share, feel free to edit this wiki page. If you have questions or want to discuss approaches, you can use the security-discuss mailinglist or Slack channel.
If you have a project that is built with Apache Maven, refer to the Configuring for Reproducible Builds guide.
Gradle builds may require setting some options in the build to ensure reproducible artifacts.
Modern Python tooling (such as Flit and Hatch) support reproducible builds for pure-Python projects. You can read more about reproducible build support in Flit reproducible build docs and Hatch reproducible build docs. It's a bit more complex if your assets require native compilation, but if you can assure that your native compilation produces reproducible libraries on its own the packaging tool will produce reproducible builds..
A few guidelines:
hatch build or flit build - it should be a fixed timestampYou can read more about reproducible build support in Flit reproducible build docs and Hatch reproducible build docs.
If you prepare source-tarball, or another .tar.gz packae you can use scripts similar to this one - which takes the same source_date_epoch and repacks the .tar.gz file to be reproducible. There are however few gotchas:
1) Make sure to remove permissions for "group" and "other" for all files that you add to the repository. This is needed because group/other permissions have different deault settings (based on umask) and clearing them is the most certain way of reproducibility. This can be done in a few ways:
git archive - "-c tar.umask=0077" removes all permissions for group/otherschmod -R og= <directory> for the directory to compress - before running the reproducible script2) if you usse git archive , you can exclude some of the directories with .gitattributes eport-ignore specification