Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think there is, definitely, and that will be a solid route out of this supply chain debacle we find ourselves in.

It will have to involve identity (public key), reputation (white list?), and signing their commits and releases (private key). All the various package managers will need to be validating this stuff before installing anything.

Then your attestation can be a manifest "here is everything that went into my product, and all of those components are also okay.

See SLSA/SBOM -> https://slsa.dev



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: