new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

ci-cd/integrity-assurance

3 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Code Signing: use code signing technologies

Code signing should be employed in CI/CD pipelines using technologies such as Sigstore or Signserver to verify code authenticity and integrity.

Code Signing: code signing is not absolute security

Code signing and related technologies are not absolute guarantors of security; the code signing process itself can be exploited. Reference NIST's Security Considerations for Code Signing for additional guidance.

Code Signing: use in-toto framework

Integration of the in-toto.io framework or similar can assist in improving integrity within the CI/CD environment by providing end-to-end integrity verification.

Give your agent this brain