Blog | G5 Cyber Security

Supply Chain Integrity: The Role of Verified Reproducible Builds

SolarWinds supply chain compromise has raised questions about how organizations can detect software tainted during the vendors development and build process. In such a build, the code can be verified as containing only code that came from the original source code. A new Linux Foundation project, the Open Source Security Foundation, is discussing whether to take on reproducible builds as a project. Most software now is not designed to be reproducible, says David Wheeler, director of open-source supply chain security at the Linux Foundation.”]

Source: https://www.databreachtoday.com/supply-chain-integrity-role-verified-reproducible-builds-a-15816

Exit mobile version