▲ | prdonahue 10 hours ago | ||||||||||||||||
We're taking a very different[1] approach at Chainguard. Essentially: building the world from GitHub repos on SLSA L2 hardened infra and delivering directly to our customers to bypass the registry threat vector (which is where vast, vast majority of attacks occur—we'll be blogging about this soon with more data). [1] https://www.chainguard.dev/unchained/announcing-chainguard-l... | |||||||||||||||||
▲ | vlovich123 9 hours ago | parent [-] | ||||||||||||||||
Doesn't really sound very different and I don't see how it helps here. This attack is just a vanilla library that you hope someone adds as a dependency and you attack the users of whoever runs the code. I fail to see how Chainguard helps at all here (not to mention this is Rust and not whatever "build 3p packages" means in a JS world). | |||||||||||||||||
|