This is a great article from @andrewnez about attestation and supply chain security, and recent approaches to it that solve a lot of problems that we otherwise insist on having over and over again.
(By "a great article" I really mean "the latest in a string of great articles").
https://nesbitt.io/2026/05/24/signing-is-for-the-bad-days.html





