This post discusses the importance of software supply chain security and the major players in the ecosystem, such as SBOM, TUF, In-Toto, Sigstore, Cosign, and SLSA. It explains their focus and interactions to ensure the security and reliability of software components.
•5m read time• From devicu.com
Table of contents
Terms #From SDLC, to CI/CD , to Software Supply Chain Security #Software Bill of Materials (SBoM) #The Update Framework (TUF) #In-Toto #Sigstore & Cosign #Supply Chain Levels for Software Artifacts (SLSA) #Summary #Sort: