Dec 19 Love0 Catching Malicious Package Releases Using a Transparency Log By OpenSSF Blog, Guest Blog Trail of Bits, with funding from OpenSSF, is improving Sigstoreās rekor-monitor to help maintainers detect malicious package releases, monitor signing identities, and strengthen software supply chain security using transparency logs.Read More