Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
by
dlor
4y ago
It's less about first-party software and more for third-party off-the-shelf stuff you might run. For first-party stuff SBOMs can definitely feel useless.
92.
▲
by
dlor
4y ago
And I hear this is improving to allow short-lived publication tokens and federation to prevent them from being leaked :)
93.
▲
by
dlor
4y ago
I agree it's nonsense. The argument appears to dodge 2FA itself and the benefits to ecosystem by instead focusing on fairness, which is subjective at best. It's not "fair" that the author has to accept the burden of 2FA,
94.
▲
by
dlor
4y ago
We've been working with PyPI to help integrate Sigstore, which makes signing (and verification) easier! sigstore.dev
95.
▲
by
dlor
4y ago
Sigstore is pretty useful on it's own as a way to sign and verify software, but it can also be used to build higher level applications like this one. Happy to answer questions!
96.
▲
Sigstore: An Update on General Availability
(blog.sigstore.dev)
5 points
by
dlor
4y ago
|
0 comments
97.
▲
by
dlor
4y ago
We used to actually run an RFC3161 timestamp server in addition to the transparency log but recently turned it down because no one was using it. I'd like to bring it back for stuff like this. https://github.com/sigstore
98.
▲
by
dlor
4y ago
I don't disagree. The current state of git signing is pretty bad. I wrote more here: https://link.medium.com/zqy8VVzAJqb I'm a maintainer on gitsign and think we can fix it though!
99.
▲
by
dlor
4y ago
We're working on fixes for both of those issues!
100.
▲
by
dlor
4y ago
We're working on a GitHub App to work around the badge issue - it will also let you specify fine-grained policies instead of just signed or unsigned. The tty issue on remote VMs is also getting fixed soon! Disclosure: I work on Sigstor
101.
▲
by
dlor
4y ago
A bunch of comments below indicated that this is technically an abuse of the CT logs. Feel free to use Sigstore instead for this, it's basically the same architecture as CT logs except we officially support and endorse this use case.
102.
▲
Privacy in Sigstore
(blog.sigstore.dev)
4 points
by
dlor
4y ago
|
0 comments
103.
▲
The Dirty Secret of Cyber Security Standards
(blog.chainguard.dev)
2 points
by
dlor
4y ago
|
0 comments
104.
▲
by
dlor
4y ago
You're assuming the pay is cash. Most CEO (and high level executive) compensation is stock, which is taxed much differently from salaries. The tax brackets have very little effect.
105.
▲
by
dlor
4y ago
We use the generic in-toto Attestation data model which could capture crev style reviews, but there are no other concrete plans that I'm aware of. To be honest, crev is pretty elegant but I find manual code review like this to be prett
106.
▲
by
dlor
4y ago
Sigstore maintainer here. I'll try to answer questions!
107.
▲
by
dlor
4y ago
Thanks! We moved some code between repos and missed that link. Its fixed now!
108.
▲
by
dlor
4y ago
This is a timely post! We're actually working on merging Distroless with Alpine for the best of both worlds. You can check out some of the progress in Apko and the new Distroless GitHub org. https://github.com/chainguar
109.
▲
Don't Panic: A Playbook for Handling Account Compromise with Sigstore
(blog.sigstore.dev)
7 points
by
dlor
4y ago
|
3 comments
110.
▲
by
dlor
4y ago
What's the rest of your stack? Do you need RUN commands, or is it a different package format we could add here?
111.
▲
by
dlor
4y ago
Thanks! They're both only a month or so old, and still moving fast. Please leave some feedback in the repo if you'd like to see anything else! Disclosure: I work at Chainguard.
112.
▲
The Principle of Ephemerality
(blog.chainguard.dev)
3 points
by
dlor
4y ago
|
0 comments
113.
▲
Maven Central and Sigstore
(central.sonatype.org)
2 points
by
dlor
5y ago
|
0 comments
114.
▲
Apko: bringing distroless nirvana to Alpine Linux
(blog.chainguard.dev)
24 points
by
dlor
5y ago
|
0 comments
115.
▲
Goodbye SDLC, Hello SSDF What Is the Secure Software Development Framework?
(blog.chainguard.dev)
2 points
by
dlor
5y ago
|
1 comments
116.
▲
by
dlor
5y ago
Not sure, there have been a few issues filed but no official reply.
117.
▲
by
dlor
5y ago
Thanks for the cosign mention! Maintainer here. The link is github.com/sigstore/cosign for anyone reading along!
118.
▲
by
dlor
5y ago
I would disagree with "Use Docker Content Trust for Docker Hub". Docker hasn't been signing official images for the last several years, so turning this on means you'll get the last correctly signed images, which happen t
119.
▲
by
dlor
5y ago
Hey Tyler! Funny to see you here. Matt and I haven't given up on this, we're giving a lot of that another try at Chainguard.
120.
▲
by
dlor
5y ago
I've been involved with the OpenSSF since the start and would be happy to answer questions about this initiative or anything else! I helped start the Scorecards, SLSA, and Sigstore projects, which are all in the OpenSSF. https:/&
More ›