THEMETASEC

Cybersecurity News, Aggregated

Chainloop: Open-source evidence store and policy engine for the software supply chain

Help Net Security · 1 hour ago Policy

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be checked afterward. Compliance and security teams get a control plane … More → The post Chainloop: Open-source evidence store and policy engine for the software supply chain appeared first on Help Net Security.

Read full story at Help Net Security →