DevOps by Default Blog

Posts tagged "Supply-Chain"

Clear

2 articles

Supply Chain Security with SLSA and Sigstore

SolarWinds, Log4Shell, and countless smaller incidents proved that software supply chains are attack vectors. Compliance frameworks now require provenance verification. We implemented SLSA and Sigstore to meet requirements and build genuine trust. The Problem “Where did this binary come …

Read more

Log4Shell: Lessons for Vulnerability Response

December 2021 delivered Log4Shell, and the subsequent weeks were chaos. A month later, we’re reflecting on what worked, what didn’t, and what we’re changing permanently. The Problem The vulnerability itself was severe—remote code execution with trivial exploitation. But the real …

Read more