Every project builds with Bazel, at a version pinned in the repository, so the same commands work in every repo.
Tools pinned in the repo
Programs a build runs (MuseScore, Chromium, ffmpeg, Python, Node) are pinned by the repository, not installed on the machine or baked into a Docker image.
Shared, trusted cache
A build step whose inputs haven’t changed is never run twice. Results come from a shared remote cache that only trusted machines can write to.