Bootstrappable Builds: How and Why

At the FOSSY conference, Timothy Sample presented on 'bootstrappable builds,' a method for creating software systems from a tiny, verifiable seed of code. This approach aims to ensure the integrity of modern software by tracing the entire build process back to its origin.
Why it matters
As software supply chain attacks become more common, bootstrappable builds offer a way to verify the security and origin of complex systems like Linux.
This year's edition of the Free and Open Source Software Yearly conference , better known as "FOSSY", moved north to the beautiful (and enormous) campus of the University of British Columbia (UBC) in Vancouver, Canada from its home for the three previous editions: Portland, Oregon, in the US. There were many different types of talks at FOSSY, from deeply technical kernel-track topics, through talks on legal and community issues, to the "FOSS in Daily Life" talks. In the "Toolchains and Other Development Tools" track, Timothy Sample gave a presentation about bootstrappable builds , which is somewhat less well-known than its cousin, reproducible builds , though LWN did look at the topic just over two years ago.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in