And my benchmark is Ken Thompson’s 1984 “Reflections on Trusting Trust” compiler backdoor. If you had to pick one modern control to most reduce that class of risk — signed artifacts, SBOMs, or reproducible builds — which would you prioritize, and why?
But reproducible builds, hands down — it’s the only one that really hits the “trusting trust” angle, especially if you add Wheeler’s diverse double-compiling: Fully Countering Trusting Trust through Diverse Double-Compiling (DDC) - Countering Trojan Horse attacks on Compilers. Signed artifacts just move the trust boundary, and SBOMs won’t reveal a compiler-injected payload. Do you have deterministic builds across your toolchain yet?