Marco Franssen 4/1/2022

OCI as attestations storage for your packages

Read Original

This technical article details a method for securing the software supply chain by storing Software Bill of Materials (SBOM) and build provenance attestations in OCI registries for packages like npm, Maven, or NuGet. It demonstrates using Sigstore's Cosign to upload and sign these artifacts, providing a workaround for better security and transparency until native package manager integration is available.

OCI as attestations storage for your packages

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser