• Login
No Result
View All Result
My Blog
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
  • Home
  • World
  • Politics
  • Business
  • Science
  • Tech
    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    What One Entrepreneur And Investor Is Saying On the Unique Growth Opportunity In the Life Science Industry

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Dubai Chamber Of Digital Economy And Entrepreneur Middle East Publish A Report On The Prospects Of The Dubai’s Digital Economy

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    Never Worry About a Low Battery with This Wireless Charger, Now $80 Off

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    5 Cybersecurity Predictions Home Users Need to Know for 2023

    Listen to Music Without Blocking Out the World with These Headphones

    Listen to Music Without Blocking Out the World with These Headphones

    Air India To Use ‘Coruson’ Software For Safety Management

    Air India To Use ‘Coruson’ Software For Safety Management

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
  • Entertainment
    • All
    • Movie
    • Music
    • Sports
    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Sea to Summit Alto TR1 Review: A Fantastic Ultralight Tent

    Prediction Engines Are Like Karma: You Get What You Stream

    Prediction Engines Are Like Karma: You Get What You Stream

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    ‘The Quarry’ Lets You Experience What’s Great About Slasher Films

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

    Summer Game Fest’s Biggest Announcement? A ‘Last of Us’ Remake

  • Lifestyle
    • All
    • Fashion
    • Health
    • Travel
    nurse

    Everything You Need To Know About Nurse Residency

    Drug detox

    Are you the right candidate for medical detox?

    The Benefit of Using Sunscreen Protection

    Gift Ideas for Celebrating a Loved One’s College Acceptance

    What are the major reasons to form gall bladder stones?

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    The ‘Dune’ Miniseries Is a Fascinating Piece of History

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    Coinbase Offered Them Dream Jobs—and Then Took Them Away

    The January 6 Hearings Are Fighting for Your Attention

    The January 6 Hearings Are Fighting for Your Attention

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    12 Best Messenger Bags (2022): Crossbody, Slings, Shoulder Bags

    Big Tech Has Become a Creature of the Swamp

    Big Tech Has Become a Creature of the Swamp

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
  • More
    • Directions
No Result
View All Result
My Blog
No Result
View All Result
Home National

Github Moves to Guard Open Source Against Supply Chain Attacks

by lacygibson
August 8, 2022
in National, World
0
Github Moves to Guard Open Source Against Supply Chain Attacks
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


After 2020 In the SolarWinds cyber espionage campaign, Russian hackers slipped tainted updates into widely used IT management platforms, and a series of other software supply chain attacks continue to demonstrate the urgent need to lock down the software chain of custody. This problem is especially pressing in open source projects, which are inherently decentralized and often ad hoc. The company this week laid out a plan to provide extended defenses for open source security, after a series of worrying compromises over widely downloaded JavaScript packages from the famous “npm” registry owned by GitHub.

GitHub, itself owned by Microsoft, announced Monday that it plans to support code signing, a kind of digital wax seal, for npm packages using the code signing platform Sigstore. The tool stems from cross-industry collaboration, making it easier for open source maintainers to verify that the code they create is the same code that ends up in packages that people around the world actually download.

“While most npm packages are open source, there is currently no guarantee that packages on npm are built from the same source code that was released,” said Justin Hutchings, director of product management at GitHub. “Supply chain attacks are on the rise, and adding signed build information to open source software packages to verify where the software came from and how it was built is a great way to reduce the attack surface.”

In other words, it’s all about creating a password-authenticated and transparent phone game.

Dan Lorenc, CEO of Chainguard, which co-developed Sigstore, emphasized that while GitHub is not the only part of the open source ecosystem, it is definitely a vital town square for the community, as it is where the vast majority of projects are stored and published their source code.However, when developers really want to download an open source application or tool, they usually go to a package manager

“You don’t install the source code directly, you usually install some compiled form of it, so something happens between the source code and the creation of the package. So far, this whole step is just a black box in open source,” explains Lorenc . “You see the code and you go to download the package, but there’s no evidence that the package came from that code or involved the same people, so that’s what GitHub is fixing.”

By providing Sigstore to package managers, every stage of the software journey is more transparent, and the Sigstore tool helps developers manage cryptographic checks and requirements as the software moves through the supply chain. Lorenc said many people were shocked to hear that these sanity checks were not in place, and that many in the open source ecosystem had long relied on blind trust. In May 2021, the Biden White House issued an executive order specifically targeting software supply chain security.

Tags: AttacksChaindevelopergithubGuardMovesOpenprogrammingSafetySourceSupplyVulnerability
lacygibson

lacygibson

Next Post
Github Moves to Guard Open Source Against Supply Chain Attacks

Github Moves to Guard Open Source Against Supply Chain Attacks

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

This 17-Year-Old Founder Is Helping Farmers Using AI

This 17-Year-Old Founder Is Helping Farmers Using AI

4 months ago
This Giant Sprinkler System Can Protect Cities from Wildfires

This Giant Sprinkler System Can Protect Cities from Wildfires

5 months ago

Popular News

    Connect with us

    • Contact
    • Read Latest News Around The World – Frapios
    Write Us at: [email protected]

    Copyright Reserved © 2022

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    Copyright Reserved © 2022

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In