Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
日本語の概要は準備中です。原文の説明を表示しています。
16 件 ・ 関連度順
概要と使いどころ
Implement software supply chain integrity verification for container builds using the in-toto framework to create cryptographically signed attestations across CI/CD pipeline steps.
日本語の概要は準備中です。原文の説明を表示しています。
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
日本語の概要は準備中です。原文の説明を表示しています。
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem monitoring. Use when vetting a new dependency, reviewing a package.json/package-lock.json during code review, checking lockfiles against a supply-chain advisory's known-bad versions, or investigating a host suspected of installing a trojanized package.
日本語の概要は準備中です。原文の説明を表示しています。
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
日本語の概要は準備中です。原文の説明を表示しています。
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation, using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, Microsoft OSSGadget's oss-find-squats, and pypi-scan. Use before adding a new dependency, as a CI/CD gate on pull requests, when reviewing an AI-generated ("slopsquatting") dependency list, or when auditing a lockfile diff for a swapped package.
日本語の概要は準備中です。原文の説明を表示しています。
Detect and prevent dependency confusion (public-over-private package name resolution) in npm, PyPI, and Maven by enumerating claimable internal package names with tools like `confused` and OWASP `dep-scan`, then enforcing source restrictions via `.npmrc`, `pip.conf`/`pyproject.toml`, and Maven `settings.xml`. Use when onboarding a repo to a supply-chain security program, auditing lockfiles/manifests for confusable dependencies, or after an incident that may have leaked internal package names.
日本語の概要は準備中です。原文の説明を表示しています。
Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.
日本語の概要は準備中です。原文の説明を表示しています。
Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.
日本語の概要は準備中です。原文の説明を表示しています。
Secure the AI model supply chain with artifact signing, provenance attestation, SBOM workflows, dependency controls, and trusted model promotion.
日本語の概要は準備中です。原文の説明を表示しています。
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
日本語の概要は準備中です。原文の説明を表示しています。
Typosquatting detection, install script analysis, dependency confusion prevention, and phantom dependency detection for npm/pip.
日本語の概要は準備中です。原文の説明を表示しています。
供应链安全时使用。适用于依赖漏洞扫描 / 镜像安全 / CI 投毒防护 / SBOM。融合 SLSA + Sigstore + Snyk + Trivy。
日本語の概要は準備中です。原文の説明を表示しています。
Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets exposure. Uses PyGithub and YAML parsing for automated audit. Use when hardening CI/CD pipelines or investigating compromised build systems.
日本語の概要は準備中です。原文の説明を表示しています。
Triage npm packages for install-script malware, exfiltration, and worming behavior.
日本語の概要は準備中です。原文の説明を表示しています。
Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.
日本語の概要は準備中です。原文の説明を表示しています。
Configure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability Tespit across repositories at enterprise scale.
日本語の概要は準備中です。原文の説明を表示しています。