• fruitycoder@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    15 hours ago

    Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!