The Signature Is Real. The Software Is Not. (opens in new tab)
Two campaigns produced cryptographically valid SLSA Build Level 3 provenance attestations for malicious packages. The signatures checked…
Read the original articleTwo campaigns produced cryptographically valid SLSA Build Level 3 provenance attestations for malicious packages. The signatures checked…
Read the original article