3 ms·
> Tools like trivvy make it possible to do the scans... Only if you didn't rip trivvy out of your organisation when it had two supply chain compromises within
by dwedge 2mo ago
> Tools like trivvy make it possible to do the scans...
Only if you didn't rip trivvy out of your organisation when it had two supply chain compromises within a month of each other earlier this year
- clbrmbr 2mo agoYikes. Man, there’s a market opening for someone to redistribute open source projects with supply chain assurances!
- inigyou 2mo agoThere's been a market for a while. In thinking of Azul Java, which is just OpenJDK but with someone to point the finger at, and costs money.
- iib 2mo agoThere is a market for that, indeed. Hardened container images and hardened CI actions have been a thing for a while, with some companies providing exactly that.