4 ms·
Yes: https://github.com/paragonie/libgossamer/blob/master/docs/tutorials/01-configuring-gossamer-client.md#step-two-configure-your-attestation-policy https://gi
by CiPHPerCoder 5y ago
Yes: https://github.com/paragonie/libgossamer/blob/master/docs/tutorials/01-configuring-gossamer-client.md#step-two-configure-your-attestation-policy https://github.com/paragonie/libgossamer/blob/master/docs/tu...
The intention was to allow security vendors to offer code reviews of open source dependencies, and you can choose which you trust. This mechanizes Linus's Law and ensures there's an audit trail with "many eyeballs".
- rectang 5y agoThis seems like critical prerequisite infrastructure, which is fantastic — although not yet what I was asking for. As far as I can tell there is not yet a way for individual WordPress installations to actually benefit. However, it seems that work is underway: https://gossamer.tools/project/wordpress https://gossamer.tools/project/wordpress > The intention was to allow security vendors to offer code reviews of open source dependencies What I care most about is just quorum publishing where multiple independent identities sign a release, so that an attacker has to compromise multiple trusted identities to execute a supply chain attack. I'm not too excited about reviews beyond that. The main thing is to upgrade collective ecosystem security by hardening automatic updates.
- CiPHPerCoder 5y agoSolving the problem you care about requires doing what I just said. :) And, yes, there is a lot of work necessary to get WordPress to use Gossamer. I can't guarantee a deadline right now, but 2022 looks hopeful.