Comment by dwedge
10 hours ago
> Tools like trivvy make it possible to do the scans...
Only if you didn't rip trivvy out of your organisation when it had two supply chain compromises within a month of each other earlier this year
10 hours ago
> Tools like trivvy make it possible to do the scans...
Only if you didn't rip trivvy out of your organisation when it had two supply chain compromises within a month of each other earlier this year
Yikes. Man, there’s a market opening for someone to redistribute open source projects with supply chain assurances!
There is a market for that, indeed. Hardened container images and hardened CI actions have been a thing for a while, with some companies providing exactly that.
There's been a market for a while. In thinking of Azul Java, which is just OpenJDK but with someone to point the finger at, and costs money.