TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Artifact Attestations–now in public beta

10 pointsby jiceaabout 1 year ago

2 comments

0xmasonabout 1 year ago
Have orgs done this manually in the past? For example, they have a private key that is stored in Github secrets and it signs the artifact upon action completion and posts it to some tamperproof registry.<p>Then anyone can verify it by checking the signature and contents against the org&#x27;s public key, which is made available somewhere.<p>This certainly seems like a UX improvement, and a simpler (and thus safer) key management process.
jauntywundrkindabout 1 year ago
Both awesome to see, but also feels like this radically speeds up the ratcheting to a world where governments directly define what software computers may and may not run. And existential threat to end-user&#x2F;general purpose computing.