••6 days ago
Supply Chain Security — SBOMs, Attestation, and What to Actually Verify
SBOMs and signed attestations sound like checkboxes until you need to answer "did this artifact come from our pipeline?" The minimum viable supply-chain story we run.