Tag provenance
GitHub Attestations and cosign both produce Sigstore signatures. The question is therefore not whether you sign, but who runs the trust infrastructure and who ultimately verifies. Why provenance evidence is needed in the first place is covered in Provenance and SLSA, in Provenance and Attestation, and in enforcing provenance in the cluster with Kyv... mehr auf muellermh.wordpress.com
GitHub Attestations oder cosign? Plan-Voraussetzung, Prüfung mit gh attestation verify und drei Kriterien, ab denen ein Wechsel zu cosign lohnt.... mehr auf muellermh.wordpress.com
Ein Cluster ohne Admission Policy zieht jedes Image, das du ihm gibst. kubectl apply oder helm install prüfen nur, ob die Referenz auflösbar ist, nicht wer sie gebaut hat. imagePullPolicy entscheidet, ob ein Image erneut gezogen wird, nicht ob dem Absender zu trauen ist. Ein kompromittiertes Registry-Credential, ein vertipptes Tag, das zufällig auf... mehr auf muellermh.wordpress.com
Seit jeher gibt es schon für fast alle Plattformen verschiedenste Emulatoren, mit denen man alte Klassiker von (S)NES, SEGA und anderen Konsolen auf aktuellen Geräten zocken kann - wahrlich nichts neues. Mit Provenance gibt es nun aber auch einen Emulator für den Apple TV, der allerdings einen kleinen Haken hat: Apple erlaubt…... mehr auf blogtogo.de
Nehmt euch fürs Wochenende nichts vor, denn es wird gezoc... mehr auf sir-apfelot.de
Eine SBOM beantwortet die Frage, was in einem Artefakt steckt. Sie beantwortet aber nicht die Frage, wie das Artefakt entstanden ist. Genau diese Lücke füllt Provenance. Eine Provenance-Attestierung ist ein signierter Nachweis darüber, aus welchem Quellcode, mit welchem Build-System und mit welcher Konfiguration ein Artefakt gebaut wurde. Wer ein C... mehr auf muellermh.wordpress.com