| ▲ | Open Source Security at Astral(astral.sh) | ||||||||||||||||||||||||||||||||||||||||||||||
| 96 points by vinhnx 2 hours ago | 11 comments | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | raphinou 31 minutes ago | parent | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
One (amongst other) big problem with current software supply chain is that a lot of tools and dependencies are downloaded (eg from GitHub releases) without any validation that it was published by the expected author. That's why I'm working on an open source, auditable, accountless, self hostable, multi sig file authentication solution. The multi sig approach can protect against axios-like breaches. If this is of interest to you, take a look at https://asfaload.com/ | |||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ramoz 6 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Created an agent skill based on this blog. Assessing my own repos now. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | sevg 42 minutes ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
FYI it was actually William Woodruff (the article author) and his team at Trail of Bits that worked with PyPI to implement Trusted Publishing. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | darkamaul an hour ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||||||||||||||
With the recent incidents affecting Trivy and litellm, I find it extremely useful to have a guide on what to do to secure your release process. The advices here are really solid and actionable, and I would suggest any team to read them, and implement them if possible. The scary part with supply chain security is that we are only as secure as our dependencies, and if the platform you’re using has non secure defaults, the efforts to secure the full chain are that much higher. | |||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ChrisArchitect 32 minutes ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||||||||||||||
Earlier submission from author: https://news.ycombinator.com/item?id=47691466 | |||||||||||||||||||||||||||||||||||||||||||||||