A security review asks the team to prove that a specific jar deployed to production was built from a specific commit, byte for byte. What three things does the project need to have in place for that proof to actually be possible, and why does each one matter?
Proving a jar came from an exact commit requires the build itself to be reproducible — the same commit has to produce byte-identical output every time it's built, on any machine — and that needs three separate things working together, not just one. First, the wrapper (./mvnw/./gradlew) pins the build tool's own version, so a different Maven or Gradle installed on the reviewer's machine, or on a different CI runner, doesn't silently change how the build behaves. Second, every dependency version has to be pinned — no version ranges, no snapshots — because those can resolve to different jars on different days even from the identical POM, which defeats reproducibility regardless of the tool. Third, the artifact's own build needs a fixed, deterministic timestamp (project.build.outputTimestamp in Maven) rather than "the moment the jar was built," because a jar's zip entries normally embed the build time, and two builds of the same source at two different moments would otherwise produce different bytes purely from that timestamp, even with identical content. All three together are what make a checksum of the shipped jar actually provable against the source commit.