SecuritySupply Chain Security: SLSA, SBOM and Sigstore for Production Artifacts
After xz, npm typosquats and build poisoning, supply chain attacks have become the most common vector. SLSA + SBOM + Sigstore is the open trio of standards that lets you prove where, how and by whom an artifact was built.