• rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 months ago

    It’s all fun and games until some asshole slips something into your trusted package manager.

    Exploits are the deal pain

    • fruitycoder@sh.itjust.works
      link
      fedilink
      arrow-up
      1
      ·
      2 months ago

      Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!