Introduction


I wrote Supply Chain Security: A Deep Dive into SBOM and Code Signing earlier. That post pinned down "what's in it" via SBOM and "who signed it" via Cosign.

But even with both of those, there's still a hole.

SolarWinds' SUNSPOT was malware that lived on the build server, swapped the source code the moment a build started, and put...