Signing artifacts, attesting builds, and why you should do both
One of the most misunderstood parts of software supply chain security is the difference between signing and attesting. It’s both getting more attention lately and with it, a lot more vendor FUD. ...