logoalt Hacker News

Onavo • yesterday at 5:31 PM • 1 reply • view on HN

There's a massive push right now from top down to have secure software supply chains. Google SBOM and SigStore. It's not an organic need but if you have government customers you don't have many options.


Replies

Dayshine • yesterday at 5:41 PM

Ironically rewriting git history is a perfect opportunity for a supply chain attack.

➕ show 1 reply