Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software
Briefly

Attacks are on the rise...vulnerabilities are coming in from vendors, open source dependencies, build phase, source control phase.
This is an area that's been really under-addressed for a long time. We're starting to finally make our peace with the fact that this is something we're really going to need to think about all through the SDLC.
Read at InfoQ
[
add
]
[
|
|
]