#securesoftwaresupplychain

2025-01-16

๐Ÿ‡ฎ๐Ÿ‡น La sicurezza della software supply chain รจ un tema fondamentale e spesso trattato con troppa superficialitร . Ne ho scritto per @GuerreDiRete

#SecureSoftwareSupplyChain

guerredirete.it/come-tracciare

Caleb Woodbine ๐ŸŽบ๐Ÿ›calebwoodbine@mastodon.nz
2024-10-10

Heck yah. Love seeing the "Verifying attestation" message on Brew while upgrading. It's using sigstore!

#brewsh #brew #sigstore #securesoftwaresupplychain

output of Brew upgrade, notably showing that build attestations are being verified on installation
2024-04-01

OpenSSH and XZ/liblzma: A nation-state attack was thwarted, what did we learn?
#Docker #Engineering #SecureSoftwareSupplyChain #Security

docker.com/blog/openssh-and-xz

Given the news of the xz backdoor, may I recommend this seminal paper from Ken Thompson's 1984 Turing Award lecture showing how a compiler with no backdoors in the source code can nevertheless propagate a backdoor.

Reflections on trusting trust | the morning paper
blog.acolyer.org/2016/09/09/re

#SecureSoftwareSupplyChain #SoftwareSupplyChain #XZBackdoor

2023-10-04

Announcing Docker Scout GA: Actionable Insights for the Software Supply Chain
#Docker #Products #DockerScout #SecureSoftwareSupplyChain

docker.com/blog/announcing-doc

Caleb Woodbine ๐ŸŽบ๐Ÿ›calebwoodbine@mastodon.nz
2023-09-21

Gave a lightning talk on Sigstore's policy controller over at the Wellington OpenShift meetup today

Here's a link to the slides!

blog.calebwoodbine.com/present

#wellington #sigstore #openshift #securesoftwaresupplychain #cosign

Caleb Woodbine ๐ŸŽบ๐Ÿ›calebwoodbine@mastodon.nz
2023-08-03

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst