Billy Lynch

153 posts

Billy Lynch

Billy Lynch

@wflynch

Software Engineer @chainguard_dev | gitsign @projectsigstore | @tektoncd | Prev: @Google

New York, NY Katılım Eylül 2012
291 Takip Edilen324 Takipçiler
Billy Lynch
Billy Lynch@wflynch·
@therealpires @mattomata @lorenc_dan GitHub API signing uses a single shared key for all users, so they need to double check the commit to make sure they're signing on behalf of the right user. Gitsign includes a unique cert bound to the user OIDC token, so it doesn't need to do this matching.
English
1
0
5
212
Billy Lynch
Billy Lynch@wflynch·
@therealpires @mattomata @lorenc_dan Nope! Gitsign doesn't enforce commit emails to match. Sometimes we want to sign with identities that don't have an email (i.e. CI runners). While matchCommitter exists, it's a convenience to use the right account - it doesn't have any weight on verification.
English
1
0
4
112
Billy Lynch retweetledi
OpenSSF
OpenSSF@openssf·
gittuf, a security layer for Git repositories, has joined the OpenSSF as a sandbox project housed under the Supply Chain Integrity Working Group. 🎉 gittuf stands out by implementing an array of features dedicated to enhancing security. Learn more today: openssf.org/blog/2024/01/1…
English
0
12
35
2.5K
Billy Lynch
Billy Lynch@wflynch·
@adityasaky @jacques_chester @decodebytes Like @adityasaky said, `gitsign attest` can store detached signatures/attestations on commits without modifying the original SHA, but it does this by storing data in a different ref space, which means things like remote branch operations won't include signatures by default. 🤷‍♂️
English
1
0
2
60
Billy Lynch
Billy Lynch@wflynch·
@adityasaky @jacques_chester @decodebytes General +1 to this! The gitsign signature format CAN support multiple signatures (the underlying format is PKCS7), but practically it's not really useful because it will cause the SHA to change, so the gitsign tool doesn't bother to support it at the moment.
English
1
0
2
55
Billy Lynch retweetledi
🦊 GitLab
🦊 GitLab@gitlab·
The future of security looks bright, you don't even need a key 🚫🔑 We partnered with @projectsigstore to help you move away from traditional keys to keyless signing. Learn how to do this by adding just a few lines in a yml file: bit.ly/3PDaJPE
English
2
9
30
10.1K
Billy Lynch retweetledi
GitGuardian
GitGuardian@GitGuardian·
Dive into the world of code signing and supply chain security with Billy Lynch from @chainguard_dev With years of experience at Google, Billy brings unique insights into securing our digital ecosystems. Don't miss this episode: youtu.be/oRCJM5beQYE #SupplyChainSecurity
YouTube video
YouTube
English
0
2
7
2.7K
Billy Lynch retweetledi
Chainguard ⛓️
Chainguard ⛓️@chainguard_dev·
🆕 Chainguard Academy is live 💜 📗OSS: SLSA, SBOMs, Wolfi, apko, melange, sigstore, etc 📙Edu: glossary, recommendations & more 📘PDocs: Images, Enforce, chainctl 🔗edu.chainguard.dev
GIF
Français
1
11
24
3.8K
Billy Lynch retweetledi
Chainguard ⛓️
Chainguard ⛓️@chainguard_dev·
🟣Software Self-Attestation With @lorenc_dan: Industry Perspectives Feat. CRob 🟣Learn everything you need to know about SSDF and CISA's Software Self-Attestation Form! Tomorrow 👇 crowdcast.io/c/self-attesta…
Chainguard ⛓️ tweet media
English
0
7
10
3.3K
Billy Lynch retweetledi
GitGuardian
GitGuardian@GitGuardian·
📝 Billy Lynch from @chainguard_dev challenged us to rethink our trust in signed commits in git. Through his session on Gitsign, he explored why and how we need to ensure the integrity of our code in the face of escalating supply chain security issues. 5/7
English
1
3
6
575
Billy Lynch retweetledi
Wolfi OS
Wolfi OS@wolfi_os·
Starting random gratitude shoutouts to the amazing people who are dedicated to OSS 🐙 First up, @puerco, who is the sBOM 💣 & 🦸‍♂️saves the world from drowning in CVE false positives w OpenVEX 🫶 has a heart of gold We appreciate you! 💜
Wolfi OS tweet media
English
0
7
24
4K
Billy Lynch retweetledi
Chainguard ⛓️
Chainguard ⛓️@chainguard_dev·
📝“Being able to sign artifacts without needing to worry about keys goes a long way to help developers secure their supply chains without needing to worry about the complexities of key management”. @wflynch cd.foundation/blog/2023/05/0…
English
0
5
8
1.1K