@lumjjb@lorenc_dan@decodebytes@sabre1041 @J0hnKjell @solomonstre@projectsigstore There's a technical component to the supply chain problem, but at its core it's about changing habits and practices of a large number of developers. Would new package manager just add an additional problem of adoption into the equation?
👇👇👇
Check out how Google Open Source Security Team (@GoogleOSS) is supporting @ReproBuilds in this next instalment in our interview series... this time between @meder and @lolamby. 🔷
👇👇👇
https://t.co/FSR1yrGrZ8
For the last few months, @lsim99 and I have been working hard on creating a reference implementation for achieving SLSA 3 and creating non-forgeable build provenance using only free tooling on GitHub Actions! Check it out. This is just the start :)
https://t.co/BPspLHMQTy
Very excited to announce Secure Open Source! Program that rewards OSS developers for a broad range of security improvements. See https://t.co/FiKEoObLo7 for details on how to participate.
https://t.co/TriLtfqzOp