Moshe Zioni

Results 12 issues of Moshe Zioni

Perhaps we should consider extending the SLSA flowchart to the left towards the step of design and decisions on this steps that leads to insecure situations (regardless of implementation in...

clarification
blocked

Further breakdown of Hermetic category into different categories and risk levels so it can better fit lower-than-L4 requirements as well.

spec-change

Current Chapter 14 tackles Build and Deploy systems, specifically describing in 14.1.1: > Verify that the application build and deployment processes are performed in a secure and repeatable way, such...

help wanted
5.0
Needs wider input

For dependency confusion use case - a keyword list option for marking risky packages that should follow a scheme for internal-facing only. That way - the user will be able...

enhancement