11 ms·
These attacks are more and more common and there's still little to actually solve them. We're working on this at Chainguard by starting at the lowest levels (a
by dlor 4y ago
These attacks are more and more common and there's still little to actually solve them.
We're working on this at Chainguard by starting at the lowest levels (a containerized Linux distro) where we can deliver packages safely. Then we can use that layer to safely deliver language packages, like in this case.
This is all being done in the open, with projects like Sigstore (sigstore.dev) and our Linix distro Wolfi (wolfi.dev).
This is an incredibly complicated space and there's no silver bullet. We need to build safe delivery mechanisms for trustworthy software.
Linux distros have traditionally done this very well, but they've struggled to solve language package manager distribution, leading developers to shy away from and work around them when installing things like PyTorch.
Our hope is that we can bring the trustworthiness of Linux distros to language package managers, and the ease of language package managers to Linux distros.
- deleted 4y ago[deleted]