GitHub: How Code Provenance Can Prevent Supply Chain Attacksahttps://www.darkreading.com/application-security/github-code-provenance-supply-chain-attacks
Through artifact attestation and the SLSA framework, GitHubs Jennifer Schelkopf argues that at least some supply chain attacks can be stopped in their tracks.