Software Supply Chain Security
Build Provenance and Artifact Signing
Use provenance, signing, verification, and protected CI/CD identities to decide whether a software artifact can be trusted.
Guidance and practical considerations for artifact signing.
1 resource
Use provenance, signing, verification, and protected CI/CD identities to decide whether a software artifact can be trusted.