Blair · @blairdrummond
6 followers · 114 posts · Server hachyderm.io

My colleagues just published an awesome ~50m demo diving into supply chain security, , and "automated governance", with . It's detailed, practical stuff that I think practitioners will enjoy --- and all the repos are public!

youtu.be/63XD4j5BCYE

github.com/search?q=org%3Aliat

#SLSA #sigstore

Last updated 1 year ago

devguy :verified: · @developerguy
354 followers · 551 posts · Server hachyderm.io

I was so excited (still I'm) about the v0.11 release of the @Docker ✨With that release, creating an and provenance for your builds has been never been easy!
I'm so glad to see that @openpolicyagent project uses these🥳✨
github.com/open-policy-agent/g

#buildkit #SBOM #SLSA #gatekeeper

Last updated 1 year ago

devguy :verified: · @developerguy
354 followers · 543 posts · Server hachyderm.io

Give Chains a try and realize how it could help you to make the software supply chain secure that you set up on @tektoncd which means that you will be 💃 Level to compliant without any hassle ↙️cd.foundation/blog/2022/10/18/

#Tekton #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
355 followers · 536 posts · Server hachyderm.io

I'm super glad to see that two of the great projects and now signed by another awesome project by @sigstore ✍️ and made 💃 provenance available, thanks to @JamesLaverack and Luca Guerra! 🚀
1️⃣github.com/jetstack/paranoia/p
2️⃣github.com/falcosecurity/falco

#falcoctl #paranoia #Cosign #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
354 followers · 536 posts · Server hachyderm.io

The v1.6.0 version of the "slsa-github-generator" project provided by the community was released a day ago which means that all my PRs are now ready to use🥳🍹
Thanks to Laurent Simon Asraa Ali @ianlewis for helping me🫶
Here is the full CHANGELOG!🚀
github.com/slsa-framework/slsa

#SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
354 followers · 535 posts · Server hachyderm.io

One of the important specifications of the software supply chain security era is no doubt 💃 and finally, it reached the v1.0 release 🚀 So, the tools that already generate SLSA provenance have to adopt that v1.0 release💡Here is the tracking issue✅
github.com/slsa-framework/slsa

#SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
353 followers · 528 posts · Server hachyderm.io

Generating the provenance for builds is one of the critical ways to trace the software back to its source and hardware and signing this metadata (attestation) proves the integrity! Great news, the deps.dev started to show💃 provenance info for npm packages!

blog.deps.dev/npm-provenance/

#SLSA

Last updated 2 years ago

Roberth Strand · @robstr
54 followers · 51 posts · Server mas.to

Deep diving into today. Definitively worth it, so much good information and reference material. slsa.dev/spec/v1.0/

#SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
352 followers · 520 posts · Server hachyderm.io

🚨The security blog by
is true gold!

🚀🥳It really helped me to learn more about software supply chain security things including .dev, , , , , , and many more!

🧑🏻‍💻I highly recommend you take a look at this blog!

security.googleblog.com/2023/0

#google #deps #go #SLSA #SBOM #scorecard #distroless

Last updated 2 years ago

devguy :verified: · @developerguy
352 followers · 518 posts · Server hachyderm.io

🛎️🚨In case you missed this folx, do not forget to register for this event unless you miss talks about , , , and many more and it is FREE for virtual attendances, what are you waiting for go and register! 🥳

events.linuxfoundation.org/ope

#SBOM #sigstore #SLSA #openssf #theopenssf #OpenSSFDay

Last updated 2 years ago

Seth Michael Larson · @sethmlarson
807 followers · 547 posts · Server fosstodon.org

Love this because it clarifies an important point for , attestation is about artifacts not releases!

"It is often difficult or impossible to determine when a release is ‘finished’ because many ecosystems allow adding new artifacts to old releases..."

slsa.dev/spec/v1.0/distributin

#python #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
346 followers · 511 posts · Server hachyderm.io
devguy :verified: · @developerguy
345 followers · 505 posts · Server hachyderm.io

🎊I'm super glad to see lots of great content related to software supply chain security on @Docker official website based on the recent development effort in v0.11 🥳
🔖 Build Attestations
📄 SBOM
🧾
💃
and many more 👇
docs.docker.com/build/attestat

#buildkit #provenance #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
345 followers · 504 posts · Server hachyderm.io

The @chainguard_dev team unchained blog is true gold🎖
You can find lots of amazing resources if you are making research about software supply chain security type of stuff:
💃
🔖
📄
and many more☝️
🏃‍♂️I highly recommend you go and take a look at it!
chainguard.dev/unchained

#SLSA #provenance #SBOM

Last updated 2 years ago

Adam Kaplan 🚌🚊🚢 · @adambkaplan
131 followers · 212 posts · Server hachyderm.io

Google somehow made catchy?

youtube.com/watch?v=NaR8WlLtPw

Also looks like there might be a few Cloud-Native Easter eggs in there...

#softwaresupplychain #SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
345 followers · 503 posts · Server hachyderm.io

🚨 The v1.0 release for is on the way since the latest final release before v1.0 is RC2 was announced recently 🥳 Before v1.0, the issue for tracking the projects that currently integrate provenance generation such as , , many more⏰
github.com/slsa-framework/slsa

#SLSA #buildx #chains

Last updated 2 years ago

devguy :verified: · @developerguy
345 followers · 501 posts · Server hachyderm.io

☝️If you are willing to become a contributor to the 💃 Generators like Trusted , , , and -based generators, you should add your e2e tests to the example package, and thanks to @ianlewis for the detailed explanation of these 🤸
github.com/slsa-framework/exam

#SLSA #go #generic #container #docker

Last updated 2 years ago

devguy :verified: · @developerguy
341 followers · 477 posts · Server hachyderm.io

🔔💃 is a framework to help improve the integrity of your project throughout its development cycle, allowing consumers to trace the final piece of software you release all the way back to the source. Now be ready for the v1.0 release⏰
➡️security.googleblog.com/2022/0

The last release RC2 is just out before releasing the actual v1.0 🎊
slsa.dev/blog/2023/04/slsa-v1-

#SLSA

Last updated 2 years ago

devguy :verified: · @developerguy
340 followers · 476 posts · Server hachyderm.io

🚨🔔HOT OF THE PRESS: Another great article published by @mlieberman☝️

A great overview through an amazing cat metaphor🐈of ensuring software supply chain security by using two of the excellent projects @sigstore and 💃 together.

Highly recommend you read it 🧐

kusari.dev/blog/whos-lurking-i

#SLSA

Last updated 2 years ago

Shaun McDonnell · @mcshauno
4 followers · 15 posts · Server hachyderm.io

RT @developerguyba
Do you want to learn more about how you can make your pipelines Level 2 compliant by using two of the popular projects @tektoncd and its supply chain manager ? Here is one of the recent blogs posts published on @GoogleOSS that may help you🆙
opensource.googleblog.com/2023

#SLSA #chains

Last updated 2 years ago