arXiv · 2407.03949
Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing
Abstract
Software engineers integrate third-party components into their applications. The resulting software supply chain is vulnerable. To reduce the attack surface, we can verify the origin of components (provenance) before adding them. Cryptographic signatures enable this. This article describes traditional signing, its challenges, and the changes introduced by next-generation signing platforms.
Explore related subjects
Keep this discovery
Taylor R. Schorlemmer, Ethan H. Burmane, Kelechi G. Kalu, Santiago Torres-Arias, James C. Davis. 2024-07-04. Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing. https://arxiv.org/abs/2407.03949
Cite the original work for its findings. Save a collection to share your selection of sources.