HNHacker News
TopNewBestAskShowJobs

dlor

1,301 karma · joined June 23, 2014

submissionscomments

OpenPubKey and Sigstore

blog.sigstore.dev·93 pts·dlor·
28

The Tyranny of Nits

leafwing-studios.com·1 pts·dlor·
0

CVSS 4.0 Is Here, but Prioritizing Patches Still a Hard Problem

darkreading.com·3 pts·dlor·
0

CWE Top Most Dangerous Software Weaknesses

cwe.mitre.org·155 pts·dlor·
128

The EU’s Product Liability Directive could kill open source

techradar.com·1 pts·dlor·
1

Elastic Stack container images signed with Sigstore

elastic.co·1 pts·dlor·
0

Shrink to Secure: Kubernetes and Secure Compact Containers

gsantoro.dev·3 pts·dlor·
0

Supply chain security for Go, Part 2: Compromised dependencies

security.googleblog.com·2 pts·dlor·
0

The Principle of Minimalism

chainguard.dev·9 pts·dlor·
0

Fully bootstrapping Java from source in Wolfi

chainguard.dev·8 pts·dlor·
0

Removing PGP from PyPI

blog.pypi.org·187 pts·dlor·
187

Sigstore: Roots of Trust for Software Artifacts

infoworld.com·1 pts·dlor·
0

He Untold Story of the Boldest Supply-Chain Hack Ever

wired.com·8 pts·dlor·
1

Feeling VEXed by software supply chain security? Us, too

theregister.com·2 pts·dlor·
0

87% of Container Images in Prod Have Critical or High-Severity Vulnerabilities

darkreading.com·3 pts·dlor·
1

Towards Easier, More Secure Signature Tech for the Java Ecosystem with Sigstore

blog.sigstore.dev·1 pts·dlor·
0

GitHub says hackers cloned code-signing certificates in breached repository

arstechnica.com·2 pts·dlor·
0

Memory safety is the new black, fashionable and fit for any occasion

theregister.com·4 pts·dlor·
0

Understanding the relationship between FOSS and the “software supply chain”

chainguard.dev·3 pts·dlor·
1

Are SBOMs Good Enough for Government Work?

chainguard.dev·1 pts·dlor·
0

Sigstore December Roundup

blog.sigstore.dev·1 pts·dlor·
0

Signatus, ergo securus? Who can sign what with TUF and Sigstore

blog.sigstore.dev·1 pts·dlor·
0

Sigstore the Easy Way

rewanthtammana.com·1 pts·dlor·
0

Iranian hackers use Log4Shell to mine crypto on federal computer system

cyberscoop.com·3 pts·dlor·
0

Software Dark Matter Is the Enemy of Software Transparency

chainguard.dev·8 pts·dlor·
0

Sigstore Verification of CPython Releases

python.org·5 pts·dlor·
0

NSA, CISA, ODNI Release Software Supply Chain Guidance for Developers

nsa.gov·4 pts·dlor·
0

What Your Scanner Doesn't Find Can Hurt You

blog.chainguard.dev·2 pts·dlor·
0

One-Third of Popular PyPI Packages Mistakenly Flagged as Malicious

darkreading.com·4 pts·dlor·
0

Minimal Container Images: Towards a More Secure Future

blog.chainguard.dev·1 pts·dlor·
0
Page 1 of 3Next →