Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Deterministic by Design - Achieving Reproducibl...

Deterministic by Design - Achieving Reproducible Builds with Maven (Devoxx BE 2026)

Modern software delivery pipelines face increasing pressure from auditors, regulators, and internal governance teams. Yet many builds remain non-reproducible. This lack of determinism creates blind spots in compliance, undermines traceability, and exposes organisations to risks when validating what actually went into production.

This session demonstrates how developers can use Apache Maven features to reliably produce identical artifacts from identical inputs. You’ll also learn how to diagnose where reproducibility breaks down and how Maven’s built-in verification tools can highlight sources of non-determinism.

Join this talk to understand why reproducibility is becoming a non-negotiable requirement for responsible software development and what you can do to make your build deterministic by design.

Avatar for Maarten Mulders

Maarten Mulders

October 08, 2026

More Decks by Maarten Mulders

Other Decks in Programming

Transcript

  1. 1. The Problem 2. Why Reproducibility Matters 3. Reproducibility with

    Apache Maven 4. Verifying Your Build 5. Wrapping up #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  2.  REPEATABILITY (running the same experiment with exact same samples)

    vs.  REPRODUCIBILITY (running the same experiment but with different samples) #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  3. REPRODUCIBILITY ~= DETERMINISM → fi fi ‑ Same source same

    artifact Common sources of non determinism: timestamps le/directory name ordering dependencies environment leakage stale les & directories #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  4. RELIABLE ARTIFACT CACHING IN CI/CD (see The Maven Build Cache

    in Practice) #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  5. CYBER RESILIENCE ACT (CRA) “ organisations must be able to

    trace what code/components ended up in the production system and how #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  6. DIGITAL OPERATIONAL RESILIENCE ACT (DORA) “ nancial organisations should have

    auditable fi change management and logs; including all software changes to be deployed in a controlled manner and full auditability of production behaviour linked to change management #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  7. NETWORK AND INFORMATION SYSTEMS DIRECTIVE (NIS2) “ requires documented and

    auditable processes that provides evidence of secure development and deployment; traceable pipelines for producing that software (implied) #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  8. MEDICAL DEVICE REGULATION (MDR) “ requires full lifecycle traceability, from

    design, ‑ through development into production and even post market; including tracing requirements to code and tests, and to track updates and changes over time #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  9. INITIAL CHECKS Project Object Model assessment - mvn artifact:check buildplan

    #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  10. FIRST STEPS 1. Pin dependency versions 2. Pin Maven plugin

    versions 3. Ensure consistent build output #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  11. 1. PIN DEPENDENCY VERSIONS ❌ Don't use this: <dependency> <groupId>org.slf4j

    groupId> <artifactId>slf4j api artifactId> <version>[2.0.0,) version> dependency> / / < / / < < - < What if a new patch version comes out tomorrow? #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  12. 1. PIN DEPENDENCY VERSIONS ✅ Do use this: <dependency> <groupId>org.slf4j

    groupId> <artifactId>slf4j api artifactId> <version>2.0.19 version> dependency> / / < / / < < - < Use Dependabot, Renovate or similar to stay up-to-date. #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  13. 2. PIN MAVEN PLUGIN VERSIONS Declare versions of each Maven

    plugin explicitly. Maven 4.x will emit a warning: Version not locked for default bindings plugins [maven-resources-plugin, maven-compiler-plugin, maven-surefire-plugin, maven-jar-plugin], you should define versions in pluginManagement section of your pom.xml or parent Again, use Dependabot, Renovate or similar to stay up-to-date. #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  14. 3. ENSURE CONSISTENT BUILD OUTPUT By default, entries in an

    archive will carry current timestamp. Even if you rebuild yesterdays version today. Setting one property prevents this: <properties> <project.build.outputTimestamp>2026-09-17T15 11 57Z properties> project.build.outputTime / < / < : : ⚠️ The Maven Release Plugin will auto-update during releases. #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  15. 3. ENSURE CONSISTENT BUILD OUTPUT Maven JAR plugin pre 3.2.0

    didn't order entries inside the JAR in a predictable way. #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  16. DEMO: IS IT REPRODUCIBLE? “ It works on my machine...

    — every developer, at some point in their career #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  17. INTRODUCING: REPRODUCIBLE CENTRAL “ Rebuild instructions for artifacts published to

    (Maven) Central Repository jvm-repo-rebuild/reproducible-central on GitHub #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  18. WHY BOTHER ABOUT VERIFICATION? Have a third, independent party 1.

    proof your binaries match the source code. → less likely to fall victim of supply chain attacks 2. proof anyone could rebuild the binaries. → ensures long-term maintainability of your project #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  19. WHY? 1. Quality: CI/CD attack protection Reliable artifact caching in

    CI/CD Long-term maintainability 2. Compliance CRA DORA NIS2 MDR #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  20. COMMON CAUSES ❌ Cause ✅ Resolution 1. Floating dependencies Don't

    use version ranges 2. Floating plugins Pin plugin versions 3. Archive timestamps not set De ne project.build.outputTimestamp 4. Environment leakage "It Depends" ™ 5. Build & publish from clean checkout fi fi Stray folders/ les #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  21. VERIFICATION When publishing on Maven Central, set-up reproducible build veri

    cation. Reproducible Builds 3/3 fi Wear your badge with pride: #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  22. EXTRA: VERIFY DOWNLOADS AGAINST EXPECTED PGP KEYS Uploading to Maven

    Central requires a valid cryptographic signature over the payload Verify PGP signatures plugin can verify PGP signatures of all project dependencies at build time. #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)
  23. REFERENCES Please give feedback! maarten.mulders.it The Road to Reproducible Builds

    on the JVM → @mthmulders ❤️ bit.ly/deterministic-by-designdemos #DeterministicByDesign #Maven Maarten Mulders (@mthmulders)