John Speed Meyers
Former Lead ResearcherChainguard
Written by John Speed Meyers

Hunting malware on package repositories
Forschung
What’s software supply chain security got to do with the State of DevOps Report? A Lot.
Nachricht
Sigstore for CISOs
Sicherheit
Do the dependency trees of widely used packages grow?
Forschung
The security costs of base image version loitering
Sicherheit
The Dirty Secret of Cybersecurity Standards
Sicherheit
SLSA vs. Software Supply Chain Attacks
Sicherheit
How to make package signing useful
Maschinenbau