{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/what-is-reproducible-build/#clm-k03-q-060",
  "claimStatus": "CURRENT TECHNICAL STANDARD",
  "correctionStatus": "CURRENT K03 RECORD",
  "id": "CLM-K03-Q-060",
  "lastReviewed": "2026-08-14",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k03-q-060.json",
  "name": "What is a reproducible build?",
  "ownerAnchor": "clm-k03-q-060",
  "ownerId": "K01-Q-060",
  "ownerRoute": "/questions/what-is-reproducible-build/",
  "ownerType": "question",
  "proposition": "A reproducible build produces byte-identical output from the same declared source, tools, inputs, and environment. It strengthens release-integrity evidence and can expose hidden variation, but it does not prove the software is correct, secure, deployed, authorized, or currently operating.",
  "qualification": "The answer is bounded by the owning topic, current source catalog, and explicit project-doctrine labels.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-14",
  "scope": "Direct answer for What is a reproducible build?",
  "slug": "clm-k03-q-060",
  "sourceIds": [
    "SRC-NIST-SSDF",
    "SRC-NIST-800-53",
    "SRC-SLSA",
    "SRC-IN-TOTO"
  ],
  "sourceSections": [
    {
      "section": "Version 1.1 final publication",
      "sourceId": "SRC-NIST-SSDF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SSDF Version 1.1 provides high-level secure software development practices.",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/final"
    },
    {
      "section": "Version 1.2 initial public draft",
      "sourceId": "SRC-NIST-SSDF",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The official NIST record identifies SSDF Version 1.2 as an initial public draft published 2025-12-17.",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/r1/ipd"
    },
    {
      "section": "Planning note — Release 5.2.0",
      "sourceId": "SRC-NIST-800-53",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "NIST issued SP 800-53 Release 5.2.0 on 2025-08-27 with specified additions and revisions.",
      "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
    },
    {
      "section": "Publication purpose",
      "sourceId": "SRC-NIST-800-53",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SP 800-53 supplies a catalog of security and privacy controls; selection and assessment remain context-dependent.",
      "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final"
    },
    {
      "section": "Specification status",
      "sourceId": "SRC-SLSA",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SLSA v1.2 is an approved specification for incrementally improving software supply-chain security.",
      "url": "https://slsa.dev/spec/v1.2/"
    },
    {
      "section": "Build requirements",
      "sourceId": "SRC-SLSA",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "SLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating.",
      "url": "https://slsa.dev/spec/v1.2/build-requirements"
    },
    {
      "section": "Project overview",
      "sourceId": "SRC-IN-TOTO",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "in-toto records what software supply-chain steps were performed, by whom and in what order to support integrity review.",
      "url": "https://in-toto.io/"
    }
  ],
  "type": "ClaimRecord"
}
