FIPS Package Dependency Management
Protestware threats: How to protect your software supply chain

Protestware threats: How to protect your software supply chain

5/9/2023 · Abubakar Siddiq Ango

What this post added

This post introduces artifact attestation for generating provenance in the in-toto format, enabling verification of build processes and achieving SLSA Level 2 compliance. It also highlights the use of private registries for enhanced control over dependencies and the integration of dependency scanning within CI pipelines to detect vulnerabilities. The post also details the use of the Dependency Proxy to reduce requests to upstream registries and mitigate the impact of upstream changes or vulnerabilities.

Read the original post ↗