Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Tuesday, March 26, 2024

CI/CD and secure supply chain

https://www.sigstore.dev/ ( & cosig https://github.com/sigstore/cosign )

https://in-toto.io/

(cf. red hat trusted software supply chain which actually embeds those open source tools)



+ backstage.io for "platform engineering"