CCS2022
Sigstore: Software Signing for Everybody
Zachary Newman, John Speed Meyers, Santiago Torres-Arias
被引用 35 次
摘要
Software supply chain compromises are on the rise. From the effects of XCodeGhost to SolarWinds, hackers have identified that targeting weak points in the supply chain allows them to compromise high-value targets such as U.S. government agencies and corporate targets such as Google and Microsoft. Software signing, a promising mitigation for many of these attacks, has seen limited adoption in open-source and enterprise ecosystems.