β
Threat Intel Engineer, runs Sources & Methods newsletter and blog
- United States
- sourcesmethods.com
- @mattreduce.com
Stars
π supply-chain
6 repositories
A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code
Witness is a pluggable framework for software supply chain risk management. It automates, normalizes, and verifies software artifact provenance.
Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded
Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security






