· @rillian
36 followers · 445 posts · Server hachyderm.io

Question about

One of the uses of transparency logs is to find sneaky deployments; maybe most of the time a package is doing what you expect, but every once in a while there's a malicious version, just for a few minutes, so it's unlikely to be found in spot checks.

Is is possible to retrieve a list of all the digests signed by a particular identity, or all the signatures on a particular registry prefix? Docs talk a lot about efficient inclusion proof given a signature but not that.

#sigstore

Last updated 1 year ago

Caleb Woodbine ✅ · @calebwoodbine
80 followers · 494 posts · Server mastodon.nz
Seth Michael Larson · @sethmlarson
967 followers · 763 posts · Server fosstodon.org

Happy friday! 🎉 Just published the report for this week, updates on registration for @ThePSF, for artifacts, and other updates.

sethmlarson.dev/security-devel

#CNA #sigstore #python

Last updated 1 year ago

Seth Michael Larson · @sethmlarson
966 followers · 753 posts · Server fosstodon.org

The signatures for are now completely verifiable as documented, thanks to all the release managers who helped make this happen!

python.org/download/sigstore

github.com/sethmlarson/verify-

#sigstore #python

Last updated 1 year ago

Blair · @blairdrummond
6 followers · 114 posts · Server hachyderm.io

My colleagues just published an awesome ~50m demo diving into supply chain security, , and "automated governance", with . It's detailed, practical stuff that I think practitioners will enjoy --- and all the repos are public!

youtu.be/63XD4j5BCYE

github.com/search?q=org%3Aliat

#SLSA #sigstore

Last updated 1 year ago

Maya :verified_paw: · @mayacostantini
165 followers · 54 posts · Server hachyderm.io

The recording for my @devconf_cz talk « An introduction to for Pythonistas » is available 💡 youtu.be/3wgdyGB5KnI

#sigstore

Last updated 1 year ago

Maya :verified_paw: · @mayacostantini
153 followers · 52 posts · Server hachyderm.io

Join me at next week and discover how to secure your Python projects with 🔐 @devconf_cz sched.co/1MYhQ

#devconf_cz #sigstore

Last updated 1 year ago

devguy :verified: · @developerguy
352 followers · 518 posts · Server hachyderm.io

🛎️🚨In case you missed this folx, do not forget to register for this event unless you miss talks about , , , and many more and it is FREE for virtual attendances, what are you waiting for go and register! 🥳

events.linuxfoundation.org/ope

#SBOM #sigstore #SLSA #openssf #theopenssf #OpenSSFDay

Last updated 2 years ago

postmodern · @postmodern
1235 followers · 1534 posts · Server ruby.social

SigStore is all the rage, and there appears to be a rubygems plugin for it, but it still says it's under development and hasn't had a commit in a while. Does anyone sign rubygems using sigstore?
github.com/sigstore/sigstore-r

#sigstore #ruby

Last updated 2 years ago

Eli Wilson 🍍 · @elijahwilson
24 followers · 167 posts · Server fosstodon.org

It makes me so happy to see mentioned at ! There's still a long road to make this as easy as verifying when doing a `pip install foo`, but this is great progress. 🙌

#sigstore #pycon

Last updated 2 years ago

Simon Josefsson · @jas
61 followers · 60 posts · Server fosstodon.org

More fun with Sigstore for your apt-get update, now with cosign verification. blog.josefsson.org/2023/04/20/

#sigstore

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
139 followers · 507 posts · Server fosstodon.org

“npm packages built on a cloud CI/CD system (like GitHub Actions) can now publish with provenance, meaning the package has verifiable links back to its source code and build instructions.”

github.blog/changelog/2023-04-

#npm #supplychain #provenance #reproduciblebuilds #github #devsecops #sigstore #javascript #nodejs #packagemanagement

Last updated 2 years ago

Simon Josefsson · @jas
60 followers · 58 posts · Server fosstodon.org

Have a sneak preview of apt-sigstore - which glues together Sigstore rekor logging and "apt-get update" in Trisquel GNU/Linux and the rest of the apt eco-system. gitlab.com/debdistutils/apt-si

#trisquel #gnu #sigstore #Rekor

Last updated 2 years ago

Berkubernetus · @fuzzychef
1218 followers · 3249 posts · Server m6n.io

Heard about ? Wanna learn how to use it? Join the tutorial in Room 107 starting in 10 minutes. @socallinuxexpo

#sigstore #kcd #kcdla #scale20x

Last updated 2 years ago

devguy :verified: · @developerguy
326 followers · 400 posts · Server hachyderm.io

This is a really great blog post by the Virtru Platform Engineering team which they talked about the strategies to secure their software supply chain by using open-source tools @sigstore
@kyverno🥇

virtru.com/blog/securing-kuber

#Cosign #sigstore #projectsigstore #kyverno #softwaresupplychainsecurity #supplychainsecurity

Last updated 2 years ago

devguy :verified: · @developerguy
326 followers · 401 posts · Server hachyderm.io

🎊I'm super glad to announce that @sigstore v2.0.0 was released officially!

☝️There were lots of🌱amazing features, 🐛bug fixes, and✨improvements included in that release!

🥇Another important milestone was achieved for the team.

blog.sigstore.dev/cosign-2-0-r

#Cosign #sigstore

Last updated 2 years ago

Brandon Mitchell · @bmitch
166 followers · 112 posts · Server fosstodon.org

Congrats to the maintainers on the v2 release!
blog.sigstore.dev/cosign-2-0-r

#sigstore #cosign

Last updated 2 years ago

Andrew Block · @sabre1041
101 followers · 450 posts · Server hachyderm.io

Java always holds a special place in my heart and its great to see supporting this ecosystem!

RT @projectsigstore@twitter.com

Towards Easier, More Secure Signature Technology for the Java Ecosystem with Sigstore blog.sigstore.dev/towards-easi

🐦🔗: twitter.com/projectsigstore/st

#sigstore #SignTheWorld

Last updated 2 years ago

mlbiam :kubernetes: · @mlbiam
158 followers · 493 posts · Server fosstodon.org

Time to get this lab with up and running for Civo Navigate.

#kubernetes #supplychain #sigstore

Last updated 2 years ago

Andrew Block · @sabre1041
95 followers · 408 posts · Server hachyderm.io

Interested in running @projectsigstore@twitter.com locally? helped develop a guide that describes everything that you need to know to get started blog.sigstore.dev/a-guide-to-r

#sigstore #transparency #supplychain #signing #trust

Last updated 2 years ago