I think if we can sufficiently isolate the build process we can solve this problem. Lot's of opportunity with our project Witness to add extra isolation. It is something we are working on. However, the real supply chain security "business problem" is just tracking everything in a standardized way. This is what the in-toto project helps with. I wrote about it here: https://www.cncf.io/blog/2023/08/17/unleashing-in-toto-the-a.... we also wrote Witness and Archivista to help solve this problem..
We have lots of work to do. https://github.com/in-toto/witnessFull disclosure, I am a member of the steering committee for in-toto and the CEO of TestifySec which is the main contributor to Witness.
fyokdrigd|2 years ago
colek42|2 years ago