Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Tenable updates Vulnerability Priority Rating scoring method to flag fewer vulnerabilities as critical

      July 24, 2025

      Google adds updated workspace templates in Firebase Studio that leverage new Agent mode

      July 24, 2025

      AI and its impact on the developer experience, or ‘where is the joy?’

      July 23, 2025

      Google launches OSS Rebuild tool to improve trust in open source packages

      July 23, 2025

      EcoFlow’s new portable battery stations are lighter and more powerful (DC plug included)

      July 24, 2025

      7 ways Linux can save you money

      July 24, 2025

      My favorite Kindle tablet just got a kids model, and it makes so much sense

      July 24, 2025

      You can turn your Google Photos into video clips now – here’s how

      July 24, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Blade Service Injection: Direct Service Access in Laravel Templates

      July 24, 2025
      Recent

      Blade Service Injection: Direct Service Access in Laravel Templates

      July 24, 2025

      This Week in Laravel: NativePHP Mobile and AI Guidelines from Spatie

      July 24, 2025

      Retrieve the Currently Executing Closure in PHP 8.5

      July 24, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      FOSS Weekly #25.30: AUR Poisoned, Linux Rising, PPA Explained, New Open Source Grammar Checker and More

      July 24, 2025
      Recent

      FOSS Weekly #25.30: AUR Poisoned, Linux Rising, PPA Explained, New Open Source Grammar Checker and More

      July 24, 2025

      How to Open Control Panel in Windows 11

      July 24, 2025

      How to Shut Down Windows 11

      July 24, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Tech & Work»Google launches OSS Rebuild tool to improve trust in open source packages

    Google launches OSS Rebuild tool to improve trust in open source packages

    July 23, 2025

    Google is hoping to improve public trust in open source projects with the launch of a new open source project called OSS Rebuild that reproduces upstream artifacts and compares the new package with the original artifact.

    According to Google, this process enables customers to verify a package’s origin, understand and repeat its build process, and customize the build. 

    “Our aim with OSS Rebuild is to empower the security community to deeply understand and control their supply chains by making package consumption as transparent as using a source repository,” Matthew Suozzo from the Google Open Source Security Team (GOSST) wrote in a blog post. 

    It can detect several types of supply chain compromise, such as source code not present in the public source repository being in published packages, build environment compromise, or stealthy backdoors, such as was seen with XZ Utils. 

    The project itself consists of an automated process for getting declarative definitions for existing packages, SLSA Build Level 3 provenance, build observability and verification tools that can be integrated into vulnerability management workflows, and infrastructure definitions so that users can run their own instances of OSS Rebuild. 

    Initially, OSS Rebuild supports Python, JavaScript/TypeScript, and Rust package registries: PyPI, npm, and Crates.io. It offers rebuild provenance for several of the most popular packages in those languages. Google implied in its blog post that it plans to extend OSS Rebuild to more package registries in the future. 

    “Our vision extends beyond any single ecosystem: We are committed to bringing supply chain transparency and security to all open source software development,” Suozzo wrote. 

    The post Google launches OSS Rebuild tool to improve trust in open source packages appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAI-enabled software development: Risk of skill erosion or catalyst for growth?
    Next Article AI and its impact on the developer experience, or ‘where is the joy?’

    Related Posts

    Tech & Work

    Tenable updates Vulnerability Priority Rating scoring method to flag fewer vulnerabilities as critical

    July 24, 2025
    Tech & Work

    Google adds updated workspace templates in Firebase Studio that leverage new Agent mode

    July 24, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Customer Account Takeovers: The Multi-Billion Dollar Problem You Don’t Know About

    Development

    How to create a mesh gradient generator in HTML, CSS and JavaScript

    Web Development
    Atomfall finally fixes the audio bug that almost made me quit

    Atomfall finally fixes the audio bug that almost made me quit

    News & Updates

    CVE-2025-5807 – WordPress Gwolle Guestbook Stored Cross-Site Scripting Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CVE-2024-13940 – Ninja Forms Webhooks SSRF Vulnerability

    May 14, 2025

    CVE ID : CVE-2024-13940

    Published : May 14, 2025, 9:15 a.m. | 2 hours, 52 minutes ago

    Description : The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.7 via the form webhook functionality. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Severity: 5.5 | MEDIUM

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    ThemeSelection

    June 25, 2025

    Using AI and Open Tools to Automate Front-End Creativity

    July 15, 2025

    CVE-2025-38154 – Linux Kernel BPF Sockmap Use After Free Vulnerability

    July 3, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.