“Building a Secure Software Supply Chain with GNU Guix”https://programming-journal.org/2023/7/1/
New refereed article on #SupplyChainSecurity in #Guix, from #bootstrapping to #ReproducibleBuilds, with a focus on secure #Git updates.
Cc: @janneke @reproducible_builds
Is #TheUpdateFramework (TUF) appropriate for #Guix?
Are #Git signed commits sufficient to authenticate a repo?
What about Git{Hub,Lab} “verified” badges?
The paper describes the checkout authentication mechanism #Guix has been using for two years.
Unlike TUF, it's tailored to functional deployment à la #Nix & #Guix
More generally, it supports off-line #Git repo authentication.
#infosec
Aquilenet, fournisseur d'accès à Internet associatif, local et militant en Aquitaine vous accueille sur son instance Mastodon !
Is #TheUpdateFramework (TUF) appropriate for #Guix?
Are #Git signed commits sufficient to authenticate a repo?
What about Git{Hub,Lab} “verified” badges?