Check out the Security Hub, open Nov 7-9 in Chicago at #KubeCon + #CloudNativeCon North America, a space to collaborate around the latest security practices.
Submit a talk: https://t.co/Z3LJVAfSJA.
Learn more: https://t.co/sa40BfqQ94.
Register: https://t.co/qStpS3rzt8.
For folks looking for some more hands-on cloud native security at @KubeCon_ , check out the Security Hub. Come for interesting discussions, project collaborations, and drive by cloud native security fixes!
https://t.co/Vp0ceZnZ8P
🛡️ Gittuf
A security layer for Git using ideas from The Update Framework
* Handles key management for repo devs
* Lets you set permissions for branches, tags, files
* Protects against Git metadata attacks
Backwards compatible with GitHub
By @openssf
https://t.co/pYVSC4VpDf
There's now a formal proposal for in-toto's graduation at the @CloudNativeFdn, opened by steering committee member @torresariass!
https://t.co/mJvfMYLSi8
Many people know of in-toto through #SLSA but don’t fully understand how they intersect. @inyourbits and I authored a brief blog post to explain how you can use in-toto for SLSA's build track and the upcoming source track! https://t.co/8aHyiJ50zD
Are you disappointed there won’t be a 0-day event for Security? Don’t be! Instead, come check out the new Security Village located inside KubeCon EU throughout the conference.
For more information, head over to -
https://t.co/0Cs0qfzeSX
#KubeConEU#SecurityVillage
#KubeCon ContribFest – in-toto and The Update Framework
Join to help us protect the Software Supply Chain with TUF, in-toto, & @projectsigstore
Oct. 27, 2:30-4pm
@jp4gs@tracymiranda@mjasay@TechRepublic TUF is already used to secure the root of trust for sigstore, and there are other in-progress ideas for extending that to use TUF to determine which sigstore signatures should be trusted
📣 Call for papers - SCORED ‘22 📣
Excited to announce this new workshop on all things SW supply chain security @acm_ccs ‘22!
Website: https://t.co/URt3oKX7aR.
Short papers and demos welcome!
@torresariass@lsim99 and I are looking forward to your submissions!
We're excited to have the supply chain security project in-toto in the #CNCF Incubator! 🙌
Read more about what the project has accomplished since joining the Sandbox 👉 https://t.co/HzfkLfyW9g
@mlbiam A system like TUF can also give you revocation so that once you discover that your ci/cd system is compromised, you can communicate to users that they shouldn't use the compromised build
@mlbiam Just a single signature from the ci/cd system doesn't protect against a compromised account. But this can be combined with attestations from the developer (possibly even with an offline key), or other stages in the development for greater assurance