Install
Secrets, Keys & SBOM
Rotation, KMS/HSM, provenance, and SBOM generation/attestation.
- 7 Tracked terms
- Last 30 days Feed window
What this topic collects on
An article joins this feed when it matches these terms. Each one is also a search of its own.
Related topics
Latest in Secrets, Keys & SBOM
Day 8 — LLM03: Supply Chain | Guardrail Gazette
21+ hour, 40+ min ago (155+ words) You didn’t build the model, the dataset, or the plugin — but you inherited every risk that comes with them.Continue reading on Medium » Day 8 — LLM03: Supply Chain | Guardrail Gazette You didn’t build the model, the dataset, or the plugin — but you…...
EU-Funded CodeSupply Offers Grants for Open Source Software Supply Chain R&D
5+ day, 3+ hour ago (48+ words) Software supply chain, security and compliance tools all depend on accurate information about the packages they analyze, but that data is often fragmented EU-funded CodeSupply is making €400,000 in grants available for open source R&D projects focused on software supply…...
How to Generate an SBOM: 12 Steps, 90 Min [2026]
6+ day, 2+ hour ago (1662+ words) This tutorial walks through generating, validating, and operationalizing SBOMs using the same open-source tools that dominate the space right now: Syft, Grype, Trivy, and Dependency-Track. By the end you will have a working pipeline that produces a CycloneDX or SPDX…...
Security Model
6+ day, 23+ hour ago (143+ words) Threat model, guard middleware, PII handling, provenance and the red-team suite. OpenSmartRoute is an LLM control plane: it decides who answers. That makes its integrity a security property in its own right (Shafran et al., "Rerouting LLM Routers", 2025). This document…...
HookAudit: Building a Supply-Chain Security Scanner Without a Supply Chain
1+ week, 1+ day ago (1185+ words) What happens when you force a security tool to inspect untrusted code using only standard-library... Tagged with opensource, node, security, javascript....
Chainguard Hits 1 Billion Container Builds With AI-Powered Software Supply Chain
1+ week, 1+ day ago (489+ words) Chainguard has surpassed one billion container build manifests, doubling its output from 500 million in six months as it scales its AI-assisted, self-correcting software supply chain platform. The milestone also covers more than 3,000 unique container images and 675,000 image versions, reflecting the…...
Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security
1+ week, 1+ day ago (488+ words) Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software supply-chain security platform. The company now maintains more than 3,000 unique container images and 675,000 image versions. The milestone reflects more than…...
TuxCare Joins JFrog's Self-Healing Software Supply Chain Security Ecosystem
1+ week, 4+ day ago (109+ words) EIN Presswire There were 2,251 press releases posted in the last 24 hours and 487,259 in the last 365 days. TuxCare Joins JFrog's Self-Healing Software Supply Chain Security Ecosystem TuxCare’s SecureChain technology brings continuously maintained, source-rebuilt open-source packages to JFrog Zero-Touch Remediation EIN Presswire…...
Основы Product Security для автомобилей и зарядных станций: термины, архитектура, фреймворки
1+ week, 4+ day ago (419+ words) Preview Современный автомобиль и зарядная станция — это уже не просто «железо», а сложные... Tagged with architecture, cybersecurity, iot, security....
The dark figure of supply chain detection
1+ week, 5+ day ago (369+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Detection engineering doesn't get that for free. If we don't have a clear, complete picture of what normal package behavior looks like, an unexpected…...