Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's a massive push right now from top down to have secure software supply chains. Google SBOM and SigStore. It's not an organic need but if you have government customers you don't have many options.
 help



Ironically rewriting git history is a perfect opportunity for a supply chain attack.

The switchover date is usually announced well in advance and any interested parties can easily verify that the conversion was authentic.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: