DEV Community

Supply Chain Security Series' Articles

Back to kt's Series
Supply Chain Security: A Deep Dive into SBOM and Code Signing
Cover image for Supply Chain Security: A Deep Dive into SBOM and Code Signing

Supply Chain Security: A Deep Dive into SBOM and Code Signing

Comments
11 min read
Sigstore Deep Dive: Unmasking the Magic Behind Keyless Verification
Cover image for Sigstore Deep Dive: Unmasking the Magic Behind Keyless Verification

Sigstore Deep Dive: Unmasking the Magic Behind Keyless Verification

Comments
18 min read
SLSA Deep Dive: Securing the Supply Chain Using Verifiable Levels
Cover image for SLSA Deep Dive: Securing the Supply Chain Using Verifiable Levels

SLSA Deep Dive: Securing the Supply Chain Using Verifiable Levels

1
Comments 1
12 min read
Why Did Docker Abandon TUF?: A Turbulent History of Container Signing
Cover image for Why Did Docker Abandon TUF?: A Turbulent History of Container Signing

Why Did Docker Abandon TUF?: A Turbulent History of Container Signing

2
Comments
10 min read
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier
Cover image for SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

Comments
11 min read
Hacking GitHub: From Tag Rewrites to Dangling Commits, Where the Git Protocol Trusts You Without Checking
Cover image for Hacking GitHub: From Tag Rewrites to Dangling Commits, Where the Git Protocol Trusts You Without Checking

Hacking GitHub: From Tag Rewrites to Dangling Commits, Where the Git Protocol Trusts You Without Checking

Comments
19 min read