Understanding GitHub Artifact Attestations
Explains GitHub's new Artifact Attestations feature for securing software supply chains, covering its architecture and SLSA compliance.
Explains GitHub's new Artifact Attestations feature for securing software supply chains, covering its architecture and SLSA compliance.
Explains using OCI registries to store SBOMs and build provenance for non-Docker packages like npm, using Cosign for security.
A technical guide on securing software supply chains using Sigstore for signing and GitHub Actions for implementing SLSA requirements.