Lemmy.World
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
eifachposteBM to Kagi Small Web Appreciated RSS FeedEnglish · 1 day ago

SHA Pinning Is Not Enough

rosesecurity.dev

external-link
message-square
0
link
fedilink
1
external-link

SHA Pinning Is Not Enough

rosesecurity.dev

eifachposteBM to Kagi Small Web Appreciated RSS FeedEnglish · 1 day ago
message-square
0
link
fedilink
A few days ago I wrote about how the Trivy ecosystem got turned into a credential stealer. One of my takeaways was “pin by SHA.” Every supply chain security guide says it, I’ve said it, every subreddit says it, and the GitHub Actions hardening docs say it.
alert-triangle
You must log in or # to comment.

Kagi Small Web Appreciated RSS Feed

kagismallweb

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 49 users / day
  • 155 users / week
  • 450 users / month
  • 574 users / 6 months
  • 44 local subscribers
  • 47 subscribers
  • 4.78K Posts
  • 107 Comments
  • Modlog
  • mods:
  • eifachposteB
  • UI: 0.19.17-6-gd2cd87b1
  • BE: 0.19.17-6-g8383dcc2d
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org