What is a build artifact, and why does reproducibility matter?
An artifact is the packaged output of a build — a compiled binary, a container image, a library archive — and reproducibility means that building the same source produces an identical artifact, every time, anywhere.
Why artifacts are produced once and promoted. The important principle: build once, deploy many times. The artifact tested in staging should be the same bytes deployed to production, not a rebuild from the same source.
Why rebuilding is dangerous. Two builds from identical source can differ — a dependency resolved to a newer version, a different compiler patch level, a different build machine configuration, an environment variable. If you rebuild for production, you deploy something that was never tested, however identical the source.
What an artifact repository does: stores built artifacts with immutable versions, so a specific build can be retrieved, deployed and rolled back to. Deploying means fetching a known artifact, not building.
Reproducible builds. Going further: the same source, built by anyone, produces bit-for-bit identical output.
Why that matters:
Verification. If a build is reproducible, anyone can build the source and confirm that a distributed binary corresponds to it. Without reproducibility, you must trust that the published binary came from the published source — and there is no way to check.
Supply chain security. This is the serious case. Compromising a build system is an extremely effective attack, because the source looks correct and the binary is not. Reproducibility makes such an attack detectable by independent rebuilding.
Debugging. Reproducing a build from months ago lets you investigate what actually shipped.
Caching. Deterministic builds allow results to be reused safely.
What prevents reproducibility, and these are the practical obstacles: timestamps embedded in output; absolute file paths; non-deterministic ordering of files or map iteration; embedded build machine identifiers; locale and timezone differences; and unpinned dependencies, which is the largest single cause.
What helps: lockfiles pinning exact dependency versions and hashes; containerised builds with a fixed base; normalising timestamps; and sorting anything with arbitrary order.
Provenance attestation — a signed statement of how an artifact was produced — is the related development, alongside software bills of materials listing what an artifact contains.