Elektrine lite

← Feed

@rradczewski@hachyderm.io

Post #797969

2026-03-20 21:17 UTC

Wow I bumped trivy today (to 0.69.3 already). We have cosign and I pin releases manually, but I don't see how I would've noticed the version was poisoned (0.69.4) if I would've bumped the dependency yesterday. Scary. I think I need to more radically rethink how to create trustworthy releases for me and how I assess trust on any third party. If compromising software is so easy and happens so quickly, would a second factor (a second human signing the release) help? And can supply chain security stay hidden behind enterprise subscriptions? https://labs.boostsecurity.io/articles/20-days-later-trivy-compromise-act-ii/

Replies (0)

No replies.