Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Defending software build pipelines from malicious attack (ncsc.gov.uk)
14 points by gjvc on Feb 3, 2021 | hide | past | favorite | 3 comments


Google team had tackled this problem for GCP and the internal technical infrastructure: [1].

It was a surprisingly hard problem, because the enforcement of build security is so widely effecting that to plug the little holes becomes a major company wide effort.

[1] https://cloud.google.com/security/binary-authorization-for-b...


I’m currently contributing to an open source project that aims to tackle the chain of custody and ensuring steps happened by trusted functionaries. It’s a very interesting problem to be working on but the more you dig in the more you realize how daunting and terrifying the problem set is.


What's the project?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: