Reproducible Builds Are Not Enough: Securing the Sandbox Around Your Build Pipeline
Reproducible builds tell you a binary matches its source, but they do not tell you the build environment itself was safe from the runner it executed on. I previously worked on container security at Twistlock, and I now build secure execution infrastructure for AI workloads at Incredibuild: CI runners, sandboxes, snapshots, caching, and reproducible environments used to keep build pipelines fast and isolated. This talk applies that experience to open source protocol engineering: how a compromised CI cache or a leaky sandbox can undermine reproducibility guarantees even when the build itself is deterministic, and concrete patterns, snapshotting, isolation boundaries, and cache hygiene, for closing that gap in a Bitcoin or Lightning implementation's build pipeline. Key takeaways: - Reproducible builds and a secure execution environment are separate guarantees, and most projects only have the first one - How a poisoned CI cache can undermine reproducibility even when the build is deterministic - Concrete sandboxing and snapshot patterns from container security and AI infrastructure work that apply to open source build pipelines