FIPS Package Dependency Management
How to enhance supply chain security with GitLab and TestifySec

How to enhance supply chain security with GitLab and TestifySec

3/16/2022 · Nicole Schwartz

What this post added

Introduces the integration of TestifySec Witness into GitLab to enhance secure software supply chain capabilities. Witness documents the entire supply chain and development progress by creating a chain of custody from code creation through deployment, including SBOM and SLSA. It verifies and records CI system data, inputs, and outputs in a verifiable and standardized way, linking AWS identity metadata to build artifacts and other CI events.

Read the original post ↗