Establishing Provenance Before Coding: Traditional and Next-Gen Signing

Autor: Schorlemmer, Taylor R., Burmane, Ethan H., Kalu, Kelechi G., Torres-Arias, Santiago, Davis, James C.
Rok vydání: 2024
Předmět:
Druh dokumentu: Working Paper
Popis: Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and changes introduced by next generation signing platforms
Databáze: arXiv