Elektrine lite

← Feed

@oots@infosec.exchange

Post #992402

2026-04-07 09:14 UTC

I had to deal a bit with the "Supply-chain Levels for Software Artifacts" (SLSA) "standard": https://slsa.dev/ IMO it's a joke, since they do not properly deal with threats from "Includ[ing] a vulnerable dependency (library, base image, bundled file, etc.)". They essentially say "A future version of this standard might deal with that": https://slsa.dev/spec/v1.2/threats This has been the main entry point of the past supply chain attacks (XZ backdoor, litellm, Shai-Hulud, ...). A supply-chain security standard that doesn't properly deal with vulnerabilities in dependencies completely misses the point. It's like installing alarms on your windows (to catch burglars trying to enter your home through the windows) when your front door doesn't have a lock. #SLSA #supplychain #supplychainsecurity #xzbackdoor #ShaiHulud #litellm

Replies (0)

No replies.