Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How to enhance supply chain security with GitLab and TestifySec

Blog post from GitLab

Post Details
Company
Date Published
Author
Nicole Schwartz
Word Count
511
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab has announced a collaboration with TestifySec to integrate the Witness open-source tool into its platform, advancing its Secure Software Supply Chain Direction. This integration addresses the increasing concern of securing software supply chains by documenting the entire process from code creation to deployment, with a focus on creating a Software Bill of Materials (SBOM) and utilizing frameworks like SLSA. Witness enhances security by verifying and recording data from CI systems in a standardized way, shifting security practices left and improving transparency around software components. This approach is in response to recent software supply chain attacks and offers a new method for securing CI systems and their artifacts, making use of verifiable cloud infrastructure data from providers like AWS. GitLab and TestifySec plan to continue developing features around this integration to further enhance security measures.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.