Catching malicious package releases using a transparency log
blog.trailofbits.com | blog | #supply-chain | #threat-detection | #sigstore | #rekor | #transparency-log | #tuf | #package-security
Summary
Trail of Bits is production-hardening Sigstore's rekor-monitor, adding Rekor v2 support and TUF integration so maintainers can detect tampering and unauthorized entries in the transparency log.
- Published
- Collected
Skip to content