ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Topic

supply chain security

3 posts

Plate 80

Lily in CI: Trying Fuzz-Based Backdoor Detection on a Real Repo

Hands-on Lily (ASE 2026) on an owned C toy: rosa/lily 0.6.0 pin, directed catch of a localhost-bind trigger, clean refactor with zero flags, discovery miss, and CI cost math.

Summary30 Sept 2026 · 8 min

Plate 13

Cosign + SBOM in CI: Sign and Attest a Container Image in One Workflow

One CI shape: build an image by digest, Syft SBOM, Cosign sign + SBOM attest, verify success, and prove wrong-key/unsigned failure — the operational follow-on to after-xz.

Summary29 Sept 2026 · 8 min

Plate 11

After xz: A Practical Supply-Chain Checklist for Solo and Small Teams

Turn the xz-utils backdoor lesson into action: tarball vs git diffs, SBOM, Sigstore Cosign, SLSA provenance, and a solo/small-team release gate you can run this week.

Summary29 Sept 2026 · 9 min
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove