Been thinking about this a lot lately, mostly because my team's been pushing to tighten, up our CI/CD posture beyond just the identity and AD stuff I usually focus on. We've got Dependabot running and SBOMs generating in CycloneDX format, and version pinning with hash validation has honestly saved us a few times. The dependency confusion angle is what keeps me up at night though - we had a close call with a scoped, package name collision a while back and it made me way more paranoid about trusted feed configuration than I used to be. One thing I'm still not fully sold on is how people are balancing auto-updates against reproducibility. Auto-PRs from Dependabot are great until one drops on a Friday and breaks something in prod because nobody reviewed it properly. SLSA Level 3 looks interesting for tamper-proof builds but I haven't seen many teams actually get there in practice. Curious what others are doing around policy-as-code for package allowlisting - is anyone using something like a package, firewall in their pipelines, and has the false positive rate from SCA tools been manageable or a constant headache?
[link] [comments]
SOCIAL SHARE CARD GENERATOR