[1]
K. Thompson, “Reflections on trusting trust,” Communications of the ACM, vol. 27, no. 8, pp. 761–763, Aug. 1984, doi: 10.1145/358198.358210.
[2]
E. Dolstra, “The purely functional software deployment model,” Utrecht University, Netherlands, 2006. [Online]. Available: http://dspace.library.uu.nl/handle/1874/7540
[3]
A. Hemel, “NixOS: the Nix based operating system,” Zenodo, 2006. doi: 10.5281/zenodo.12906987.
[4]
“Nixpkgs: Nix Packages collection & NixOS.” GitHub. Accessed: Jul. 21, 2025. [Online]. Available: https://github.com/NixOS/nixpkgs/tree/92c2e04a475523e723c67ef872d8037379073681
[5]
“Guix: Transactional package manager, declarative GNU/Linux distribution, reproducible deployment tool, and more!” Codeberg. Accessed: Sep. 25, 2025. [Online]. Available: https://codeberg.org/guix/guix
[6]
J. Nieuwenhuizen and L. Courtès, “The Full-Source Bootstrap: Building from source all the way down,” Apr. 26, 2023. Accessed: Sep. 25, 2025. [Online]. Available: https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-building-from-source-all-the-way-down/
[7]
J. Hamilton and others, “Aux Foundation: A full binary bootstrap chain for Nix.” Mar. 30, 2025. Accessed: Sep. 25, 2025. [Online]. Available: https://git.auxolotl.org/auxolotl/foundation
[8]
S. Tyler and others, “live-bootstrap.” GitHub. Accessed: Sep. 25, 2025. [Online]. Available: https://github.com/fosslinux/live-bootstrap
[9]
D. Tolnay, “Bootstrapping rustc from source.” Accessed: Dec. 13, 2025. [Online]. Available: https://github.com/dtolnay/bootstrap
[10]
Bootstrappable Builds, “From C++ to Java.” Accessed: Dec. 13, 2025. [Online]. Available: https://www.bootstrappable.org/projects/java.html
[11]
“CVE-2024-3094.” Mar. 29, 2024. Accessed: Oct. 20, 2025. [Online]. Available: https://www.cve.org/CVERecord?id=CVE-2024-3094
[12]
C. Lamb and S. Zacchiroli, “Reproducible Builds: Increasing the Integrity of Software Supply Chains,” IEEE Software, vol. 39, no. 2, pp. 62–70, Mar. 2022, doi: 10.1109/MS.2021.3073045.
[13]
T. Hufschmitt, “RFC 0062: Content-addressed paths.” Accessed: Oct. 21, 2025. [Online]. Available: https://github.com/tweag/rfcs/blob/cas-rfc/rfcs/0062-content-addressed-paths.md
[14]
T. Hufschmitt, “Implementing a content-addressed Nix.” Accessed: Oct. 21, 2025. [Online]. Available: https://www.tweag.io/blog/2021-12-02-nix-cas-4/