|
|
|
|
|
by raphinou
77 days ago
|
|
One (amongst other) big problem with current software supply chain is that a lot of tools and dependencies are downloaded (eg from GitHub releases) without any validation that it was published by the expected author. That's why I'm working on an open source, auditable, accountless, self hostable, multi sig file authentication solution. The multi sig approach can protect against axios-like breaches. If this is of interest to you, take a look at https://asfaload.com/ |
|
[0] https://docs.github.com/en/actions/how-tos/secure-your-work/...