Secrets, Keys & SBOM

Rotation, KMS/HSM, provenance, and SBOM generation/attestation.

  • 7 Tracked terms
  • Last 30 days Feed window

What this topic collects on

An article joins this feed when it matches these terms. Each one is also a search of its own.

Latest in Secrets, Keys & SBOM


devops.com > eu-funded-codesupply-offers-grants-for-open-source-software-supply-chain-rd

EU-Funded CodeSupply Offers Grants for Open Source Software Supply Chain R&D

6+ day, 21+ min ago   (48+ words) Software supply chain, security and compliance tools all depend on accurate information about the packages they analyze, but that data is often fragmented EU-funded CodeSupply is making €400,000 in grants available for open source R&D projects focused on software supply…...


tech-insider.org

How to Generate an SBOM: 12 Steps, 90 Min [2026]

6+ day, 23+ hour ago   (1662+ words) This tutorial walks through generating, validating, and operationalizing SBOMs using the same open-source tools that dominate the space right now: Syft, Grype, Trivy, and Dependency-Track. By the end you will have a working pipeline that produces a CycloneDX or SPDX…...


opensmartroute.ai > docs > SECURITY

Security Model

1+ week, 20+ hour ago   (143+ words) Threat model, guard middleware, PII handling, provenance and the red-team suite. OpenSmartRoute is an LLM control plane: it decides who answers. That makes its integrity a security property in its own right (Shafran et al., "Rerouting LLM Routers", 2025). This document…...


dev.to > bappadala_rohithkumarna > hookaudit-building-a-supply-chain-security-scanner-without-a-supply-chain-1aec

HookAudit: Building a Supply-Chain Security Scanner Without a Supply Chain

1+ week, 2+ day ago   (1185+ words) What happens when you force a security tool to inspect untrusted code using only standard-library... Tagged with opensource, node, security, javascript....


cyberpress.org > chainguard-hits-1-billion-container

Chainguard Hits 1 Billion Container Builds With AI-Powered Software Supply Chain

1+ week, 2+ day ago   (489+ words) Chainguard has surpassed one billion container build manifests, doubling its output from 500 million in six months as it scales its AI-assisted, self-correcting software supply chain platform. The milestone also covers more than 3,000 unique container images and 675,000 image versions, reflecting the…...


gbhackers.com > chainguard-hits-1-billion-build-manifests

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

1+ week, 2+ day ago   (488+ words) Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software supply-chain security platform. The company now maintains more than 3,000 unique container images and 675,000 image versions. The milestone reflects more than…...


einpresswire.com > article > 93/90/84249 > tuxcare-joins-jfrog-s-self-healing-software-supply-chain-security-ecosystem

TuxCare Joins JFrog's Self-Healing Software Supply Chain Security Ecosystem

1+ week, 5+ day ago   (109+ words) EIN Presswire There were 2,251 press releases posted in the last 24 hours and 487,259 in the last 365 days. TuxCare Joins JFrog's Self-Healing Software Supply Chain Security Ecosystem TuxCare’s SecureChain technology brings continuously maintained, source-rebuilt open-source packages to JFrog Zero-Touch Remediation EIN Presswire…...


dev.to > ivan-piskunov > osnovy-product-security-dlia-avtomobiliei-i-zariadnykh-stantsii-tierminy-arkhitiektura-frieimvorki-8b3

Основы Product Security для автомобилей и зарядных станций: термины, архитектура, фреймворки

1+ week, 5+ day ago   (419+ words) Preview Современный автомобиль и зарядная станция — это уже не просто «железо», а сложные... Tagged with architecture, cybersecurity, iot, security....


aikido.dev > blog > dark-figure-supply-chain-detection

The dark figure of supply chain detection

1+ week, 5+ day ago   (369+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Detection engineering doesn't get that for free. If we don't have a clear, complete picture of what normal package behavior looks like, an unexpected…...


opensourceforu.com > 2026 > 09 > broadcom-introduces-truesource-for-open-source-security

Broadcom Introduces TrueSource for Open-Source Security

1+ week, 6+ day ago   (283+ words) Open Source For You TrueSource is a new Broadcom software portfolio that provides enterprise support, security patches and verified software artifacts for organisations using open-source technologies. Broadcom has introduced TrueSource, a new portfolio of services designed to help enterprises manage…...