Enhancing trust for SGX enclaves - By Artur Cygan
Creating reproducible builds for SGX enclaves used in privacy-oriented dep... https://blog.trailofbits.com/2024/01/26/enhancing-trust-for-sgx-enclaves/ #confidentialcomputing #ecosystemsecurity #supplychain #opensource
Enhancing trust for SGX enclaves

By Artur Cygan Creating reproducible builds for SGX enclaves used in privacy-oriented deployments is a difficult task that lacks a convenient and robust solution. We propose using Nix to achieve re…

Trail of Bits Blog
Celebrating our 2023 open-source contributions - At Trail of Bits, we pride ourselves on making our best tools open source, such as Slithe... https://blog.trailofbits.com/2024/01/24/celebrating-our-2023-open-source-contributions/ #ecosystemsecurity #machinelearning #cryptography #supplychain #blockchain #opensource #osquery
Celebrating our 2023 open-source contributions

At Trail of Bits, we pride ourselves on making our best tools open source, such as Slither, PolyTracker, and RPC Investigator. But while this post is about open source, it’s not about our tools… In…

Trail of Bits Blog
Adding build provenance to Homebrew - By William Woodruff
This is a joint post with Alpha-Omega—read their announcement post as... https://blog.trailofbits.com/2023/11/06/adding-build-provenance-to-homebrew/ #engineeringpractice #ecosystemsecurity #cryptography #opensource
Adding build provenance to Homebrew

By William Woodruff This is a joint post with Alpha-Omega—read their announcement post as well! We’re starting a new project in collaboration with Alpha-Omega and OpenSSF to improve the transparenc…

Trail of Bits Blog
Trusted publishing: a new benchmark for packaging security - Read the official announcement on the PyPI blog as well!
For the past year, we’ve ... https://blog.trailofbits.com/2023/05/23/trusted-publishing-a-new-benchmark-for-packaging-security/ #engineeringpractice #ecosystemsecurity
Trusted publishing: a new benchmark for packaging security

Read the official announcement on the PyPI blog as well! For the past year, we’ve worked with the Python Package Index to add a new, more secure authentication method called “trusted publishing.” T…

Trail of Bits Blog