Post #797969
2026-03-20 21:17 UTC
Wow I bumped trivy today (to 0.69.3 already). We have cosign and I pin releases manually, but I don't see how I would've noticed the version was poisoned (0.69.4) if I would've bumped the dependency yesterday. Scary.
I think I need to more radically rethink how to create trustworthy releases for me and how I assess trust on any third party.
If compromising software is so easy and happens so quickly, would a second factor (a second human signing the release) help? And can supply chain security stay hidden behind enterprise subscriptions?
https://labs.boostsecurity.io/articles/20-days-later-trivy-compromise-act-ii/
Replies (0)
No replies.