- A reading list for software supply-chain security. https://github.com/chainguard-dev/ssc-reading-list 2 comments kubernetes
Linking pages
Linked pages
- Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies | by Alex Birsan | Medium https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610 661 comments
- npm Blog Archive: kik, left-pad, and npm http://blog.npmjs.org/post/141577284765/kik-left-pad-and-npm 536 comments
- Cloud Native Computing Foundation https://www.cncf.io/ 328 comments
- A Log4J Vulnerability Has Set the Internet 'On Fire' | WIRED https://www.wired.com/story/log4j-flaw-hacking-internet/ 138 comments
- Sigstore https://sigstore.dev/ 106 comments
- Vulnerability Management for Go - The Go Programming Language https://go.dev/blog/vuln 90 comments
- Hacking 3,000,000 apps at once through CocoaPods https://justi.cz/security/2021/04/20/cocoapods-rce.html 89 comments
- Home - Open Source Security Foundation https://openssf.org/ 74 comments
- An open-source append only ledger | Trillian https://transparency.dev/ 49 comments
- https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf 46 comments
- Certificate Transparency - Web security | MDN https://developer.mozilla.org/en-US/docs/Web/Security/Certificate_Transparency 44 comments
- Security/Binary Transparency - MozillaWiki https://wiki.mozilla.org/Security/Binary_Transparency 38 comments
- Gossamer: Supply Chain Security for Open-Source Software https://gossamer.tools 33 comments
- GitHub - renovatebot/renovate: Universal dependency update tool that fits into your workflows. https://github.com/renovatebot/renovate 19 comments
- GitHub - anchore/grype: A vulnerability scanner for container images and filesystems https://github.com/anchore/grype 17 comments
- Remote Code Execution on rubygems.org https://justi.cz/security/2017/10/07/rubygems-org-rce.html 13 comments
- PHP Supply Chain Attack on Composer | Sonar https://blog.sonarsource.com/php-supply-chain-attack-on-composer 8 comments
- OpenID Connect | OpenID http://openid.net/connect/ 4 comments
- Compromising Thousands of Websites Through a CDN https://justi.cz/security/2018/05/23/cdn-tar-oops.html 4 comments
- SLSA • Supply-chain Levels for Software Artifacts http://slsa.dev/ 3 comments
Would you like to stay up to date with DevOps? Checkout DevOps
Weekly.
Related searches:
Search whole site: site:github.com
Search title: GitHub - chainguard-dev/ssc-reading-list: A reading list for software supply-chain security.
See how to search.