Only strictly verified and digitally signed source code is allowed in Kicksecure, blocking execution of unauthorized or tampered software.

#Kicksecure #DigitalSignatures #SecureSupplyChain #SoftwareIntegrity #OpenSourceSecurity

Demonstrably Secure Software Supply Chains with Nix

Discover how Nix can revolutionize your software supply chain security, enabling verifiable integrity and offline rebuilds from source.

Nixcademy

XZ panel with some of our @EclipseFdn community members there.

#SecureSupplyChain #JavaLand
@eclipseadoptium @jakartaee

At the heart of the CVE process and the matching done with the NVD database is the name of the manufacturer and the artefact - the software, system, library or mobile application. It's vital for this to work that the name in the #SBOM is correct to make the match work. The community has developed #PURL - package URL - to improve but so far the CVE/NVD eco system has not adopted PURL.

This needs to be fixed to make sure that the name in the SBOM matches the right set of vulnerabilities.

#SBOM #securesupplychain #CycloneDX #OpenVEX #VEX #OpenSource

secure supply chains alone secure software do not make
#sbom #slsa #securesupplychain