Technology
Linux Foundation is making it easier to verify the authenticity of software – TechRadar
New service will be free to use for everyone
In a bid to secure the open source software supply chain, the Linux Foundation, together with Red Hat, Google, and Purdue University have combined to launch a new project to help developers cryptographically sign their software.
Considering the constant increase in the rate of industrial adoption of open source software, the project, called sigstore, aims to prevent an attack on a public software repository from injecting tainted code in the supply chain.
sigstore enables all open source communities…
Continue Reading
