I summarized in the @univention Blog our activities about Supply Chain security with an overview about Signatures, SBOMs and VEX, gave some entrypoints why this matters for the Cyber Resiliance Act #CRA and BSI Base Protection and links into the Nubus documentation on how to ensure the software you are deploying is from Univention and not an attacker: https://www.univention.com/blog-en/2026/04/secure-software-supply-chains-nubus-sbom-vex-signatures/
@univention
, Linux enthusiast, family guy
| Pronomen | he/him |




Univention


