
Parth Patel
149 posts

Parth Patel
@pxp928
Kusari - Software Supply Chain Security




📝 SBOMs are critical for a handful of reasons: #visibility into dependencies, enhance #security, meet #compliance and streamline development. Learn how Google is using our Syft #SBOM #opensource #SBOM tool in our upcoming webinar. get.anchore.com/how-sboms-prot…

Model storage under attack (techcrunch.com/2024/05/31/hug…). Models are uninspectable, so the only solution to prevent tampering is to sign them. OpenSSF has a model signing SIG as part of the AI/ML WG. Both biweekly meetings are in the OpenSSF calendar. Also, github.com/sigstore/model…


🔒 The vast majority of the world's software runs on open source code. Read this article by @Gizmodo to discover how OpenSSF's initiatives, such as Sigstore and GUAC, are shaping a more secure open source software ecosystem. gizmodo.com/open-source-cy… #OSSSecurity

Since all model serialization formats are vulnerable, it is better to sign models on training (or upload) and verify signatures before use. Much better to also record the entire supply chain provenance. Will have more on this, soon

GUAC has joined the OpenSSF as an Incubating Project 🎉 GUAC is an open source supply chain security project that provides dependency management and actionable insights into the security of software supply chains. Read the announcement: openssf.org/blog/2024/03/0… #OSSSecurity














🥑+🤖🧠=🔐 We got a super exciting GUAC community meeting coming up this week... which may or may not feature some LLMs!! Come join us and see some cool demos from @ridhoq @sozercan and more! Meeting invite details at guac.sh/community
