
3/16/2022 · Nicole Schwartz
What this post added
Introduces the integration of TestifySec Witness into GitLab to enhance secure software supply chain capabilities. Witness documents the entire supply chain and development progress by creating a chain of custody from code creation through deployment, including SBOM and SLSA. It verifies and records CI system data, inputs, and outputs in a verifiable and standardized way, linking AWS identity metadata to build artifacts and other CI events.