John Speed Meyers
Former Lead ResearcherChainguard
Written by John Speed Meyers

Hunting malware on package repositories
research
What’s software supply chain security got to do with the State of DevOps Report? A Lot.
news
Sigstore for CISOs
security
Do the dependency trees of widely used packages grow?
research
The security costs of base image version loitering
security
The Dirty Secret of Cybersecurity Standards
security
SLSA vs. Software Supply Chain Attacks
security
How to make package signing useful
engineering