Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Securing the software supply chain with the SLSA framework

Summary

An overview of the SLSA framework's Build Levels 1-3, signed build provenance from CI/CD platforms, PEP 740 bringing SLSA provenance to PyPI, and how consumers can verify artifact origins.
Published
Collected

original ↗

Related coverage

back