Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Markets flatline amid Trump’s delay on Iran and potential Fed cuts in July

    June 20, 2025

    Trump Melts Down And Demands Nobel Prize As He Is About To Start A War In The Middle East

    June 20, 2025

    Fruits and vegetables could improve sleep by 16%, new research shows

    June 20, 2025
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»Github Moves to Guard Open Source Against Supply Chain Attacks
    Technology

    Github Moves to Guard Open Source Against Supply Chain Attacks

    By AdminAugust 9, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Github Moves to Guard Open Source Against Supply Chain Attacks


    Following the 2020 SolarWinds cyberespionage campaign, in which Russian hackers slipped tainted updates into a widely used IT management platform, a series of further software supply chain attacks continues to highlight the urgent need to lock down software chains of custody. And the issue is particularly pressing in open source, where projects are inherently decentralized and often ad hoc endeavors. After a series of worrying compromises to widely downloaded JavaScript software packages from the prominent “npm” registry, which is owned by GitHub, the company laid out a plan this week to offer expanded defenses for open source security.

    GitHub, which itself is owned by Microsoft, announced on Monday that it plans to support code signing, a sort of digital wax seal, for npm software packages using the code-signing platform Sigstore. The tool grew out of cross-industry collaboration to make it much easier for open source maintainers to verify that the code they create is the same code that ends up in the software packages actually being downloaded by people worldwide.

    “While most npm packages are open source, there’s currently no guarantee that a package on npm is built from the same source code that’s published,” says Justin Hutchings, GitHub’s director of product management. “Supply chain attacks are on the rise, and adding signed build information to open source packages that validates where the software came from and how it was built is a great way to reduce the attack surface.”

    In other words, it’s all about creating a cryptographically verified and transparent game of telephone. 

    Dan Lorenc, CEO of Chainguard, which co-develops Sigstore, emphasizes that while GitHub isn’t the only component of the open source ecosystem, it’s an absolutely crucial town square for the community because it’s where the vast majority of projects store and publish their source code. When developers actually want to download open source applications or tools, though, they typically go to a package manager 

    “You don’t install source code directly, you usually install some compiled form of it, so something has happened in between the source code and the creation of the package. And up until now, that whole step has just been a black box in open source,” Lorenc explains. “You see the code and then go and download the package, but there’s nothing that proves that the package came from that code or the same person was involved, so that’s what GitHub is fixing.”

    By offering Sigstore to package managers, there’s much more transparency at every stage of the software’s journey, and the Sigstore tools help developers manage cryptographic checks and requirements as software moves through the supply chain. Lorenc says that many people are shocked to hear that these integrity checks aren’t already in place and that so much of the open source ecosystem has been relying on blind trust for so long. In May 2021, the Biden White House issued an executive order that specifically addressed software supply chain security. 



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous Article‘Dry lightning’ sparked the most destructive wildfires in California
    Next Article Florida attorney general: FBI’s ‘respect’ hinges on this case

    RELATED POSTS

    Anthropic says most AI models, not just Claude, will resort to blackmail

    June 20, 2025

    The 6 Best OLED TVs (2025)

    June 20, 2025

    SpaceX’s Starship blows up ahead of 10th test flight

    June 19, 2025

    Hot Octopuss Pulse Duo Review: Not for Penetration

    June 19, 2025

    Multiplier, founded by ex-Stripe exec, nabs $27.5M to fuel AI-powered accounting roll-ups

    June 18, 2025

    Far-Right ‘Appeal to Heaven’ Flag Flown Above Government Agency in DC

    June 18, 2025
    latest posts

    Markets flatline amid Trump’s delay on Iran and potential Fed cuts in July

    The S&P 500 dipped 0.2% on Friday as investors waited on President Donald Trump’s next…

    Trump Melts Down And Demands Nobel Prize As He Is About To Start A War In The Middle East

    June 20, 2025

    Fruits and vegetables could improve sleep by 16%, new research shows

    June 20, 2025

    Anthropic says most AI models, not just Claude, will resort to blackmail

    June 20, 2025

    Could Israel’s bombing trigger a nuclear accident in Iran?

    June 20, 2025

    Wes Anderson’s Movies Ranked From Worst to Best

    June 20, 2025

    Mystery At Blind Frog Ranch Mysterious Masked Man Spooks Fans

    June 20, 2025
    Categories
    • Books (588)
    • Business (5,494)
    • Film (5,430)
    • Lifestyle (3,535)
    • Music (5,483)
    • Politics (5,481)
    • Science (4,841)
    • Technology (5,427)
    • Television (5,104)
    • Uncategorized (1)
    • US News (5,481)
    popular posts

    How Motionless in White’s Chris Motionless Learned to Scream

    Motionless in White frontman Chris Motionless is the latest guest on Loudwire’s “How I Learned…

    Jonathon Johnson proves he’s not ‘holding a grudge’ after Jenn Tran dumped him on The Bachelorette

    September 8, 2024

    Vodafone and Three’s $19B merger cleared by UK regulators — with conditions

    December 5, 2024

    Kandi & Fatum Say Marlo’s Digs at Kenya’s Daughter Were Cut From RHOA

    July 27, 2022
    Archives
    Browse By Category
    • Books (588)
    • Business (5,494)
    • Film (5,430)
    • Lifestyle (3,535)
    • Music (5,483)
    • Politics (5,481)
    • Science (4,841)
    • Technology (5,427)
    • Television (5,104)
    • Uncategorized (1)
    • US News (5,481)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Wes Anderson’s Movies Ranked From Worst to Best

    June 20, 2025

    Mystery At Blind Frog Ranch Mysterious Masked Man Spooks Fans

    June 20, 2025

    1. Finance Assignment Help With Affordable Packages

    June 20, 2025
    © 2025 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT