DiscoverSoftware Engineering Institute (SEI) Podcast SeriesUnderstanding Container Reproducibility Challenges: Stopping the Next Solar Winds
Understanding Container Reproducibility Challenges: Stopping the Next Solar Winds

Understanding Container Reproducibility Challenges: Stopping the Next Solar Winds

Update: 2025-07-30
Share

Description

Container images are increasingly being used as the main method for software deployment, so ensuring the reproducibility of container images is becoming a critical step in protecting the software supply chain. In practice, however, builds are often not reproducible due to elements of the build environment that rely on nondeterministic factors such as timestamps and external dependencies. Lack of reproducibility can lead to lack of trust, broken builds, and possibly mask hidden malware insertion. Vessel, a recent tool from the Carnegie Mellon University Software Institute (SEI), helps developers identify the difference between two container images to help sort benign from problematic issues. In this SEI Podcast, Kevin Pitstick, a senior software engineer at the SEI and Vessel’s lead developer, and Lihan Zhan, a software engineer at the SEI working on tactical and AI-enabled systems, sit down with Grace Lewis, lead of the Tactical and AI-Enabled Systems (TAS) applied research and development team at the SEI, to discuss the Vessel tool, its development, and application in mission-critical settings.  

 

Comments 
In Channel
Deploying on the Edge

Deploying on the Edge

2025-05-2801:01:02

loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Understanding Container Reproducibility Challenges: Stopping the Next Solar Winds

Understanding Container Reproducibility Challenges: Stopping the Next Solar Winds

Kevin Pitstick, Lihan Zhan, and Grace Lewis