CCS2022

Sigstore: Software Signing for Everybody

Zachary Newman, John Speed Meyers, Santiago Torres-Arias

被引用 35 次

摘要

Software supply chain compromises are on the rise. From the effects of XCodeGhost to SolarWinds, hackers have identified that targeting weak points in the supply chain allows them to compromise high-value targets such as U.S. government agencies and corporate targets such as Google and Microsoft. Software signing, a promising mitigation for many of these attacks, has seen limited adoption in open-source and enterprise ecosystems.