home / channels / provenance

provenance / supply chain

fulcio · rekor · tesseract · dual-signed bundles
2026.03.20Modeling hackerbot-claw Against My Own CI/CDA single pull_request_target misstep turns a trusted GitHub workflow into a supply-chain backdoor.2026.03.18Running Your Own Transparency InfrastructureThe full Sigstore trust stack, self-hosted from a YubiKey CA up. No public good instance required.
view all posts →