OmniBOR's Avatar

OmniBOR

@omnibor.io

Reproducible identifiers & fine-grained build dependency tracking for software artifacts. ๐ŸŒ Website: omnibor.io ๐Ÿ’ป GitHub: https://github.com/omnibor ๐Ÿ’ฌ Discord: https://discord.gg/3xNx4syYpf

16
Followers
0
Following
8
Posts
10.02.2025
Joined
Posts Following

Latest posts by OmniBOR @omnibor.io

We will continue to post all documentation publicly on our website and our GitHub repositories, and remain fully committed to transparency in all issues. Our project Zoom calls remain open to all, and so do our GitHub Discussions page and issue trackers.

28.04.2025 17:32 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Join the OmniBOR Discord Server! Discussion and project coordination for OmniBOR, reproducible identifiers and fine-grained build dependency tracking for software artifacts. | 4 members

The OmniBOR project now has a Discord server! discord.gg/3xNx4syYpf

Discord was chosen after extensive discussion and a vote.

We want to thank all participants and the OpenSSF for letting us previously have a channel on their Slack workspace despite OmniBOR not being an OpenSSF project.

28.04.2025 17:32 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

We also have several in-progress implementations:

Rust: github.com/omnibor/omni...
Go: github.com/omnibor/omni...
C#: github.com/omnibor/omni...
Python: github.com/omnibor/omni...

17.04.2025 16:55 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

If that sounds interesting to you, come learn more!

Our website: omnibor.io
Our spec: github.com/omnibor/spec

17.04.2025 16:55 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

With both combined you have a beautiful Merkle Tree-like structure. Any change in a build input causes all artifacts derived from it to have new Artifact IDs. With the Input Manifests, you can detect exactly what artifacts changed.

It's a full Artifact Dependency Graph, from some small text files!

17.04.2025 16:52 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Input Manifests are the other half of OmniBOR.

They're short files recording Artifact IDs of build inputs for an artifact, plus Artifact IDs of those inputs' own Input Manifests if they have one.

After you build an artifact, you can embed the Artifact ID of its Input Manifest in it!

17.04.2025 16:52 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Artifact IDs are one half of the OmniBOR spec.

They're short, reproducible identifiers for artifacts like binaries and source files.

An Artifact ID is a Git object identifier, using SHA-256 for hashing, with the "blob" type, and newlines normalized to Unix style.

17.04.2025 16:52 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Is this thing on? This is a new official Bluesky account for the OmniBOR project.

OmniBOR is a spec for reproducible software identifiers and fine-grained dependency tracking. It's an open project anyone can join!

Our website is omnibor.io

Hi Bluesky! ๐Ÿ‘‹

16.04.2025 19:14 ๐Ÿ‘ 4 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0