About the Author

Luke Hinds is the CTO of Stacklok. He is the creator of the open source project sigstore, which makes it easier for developers to sign and verify software artifacts. Prior to Stacklok, Luke was a distinguished engineer at Red Hat.

More posts by this author (9)

Introducing the Frizbee GitHub Action to automate pinning actions and container images to digests

Radoslav Dimitrov / Luke Hinds /
Jun 20, 2024
Continue Reading

Python typosquatting attack targets popular open source PyPI library with 30M weekly downloads

Luis Juncal / Luke Hinds /
Jun 6, 2024
Continue Reading

Announcing the Proof-of-Diligence (PoD) algorithm: A method of modeling trust and maintainability in open source ecosystems

Luke Hinds / Pankaj Telang /
Apr 17, 2024
Continue Reading

An analysis of an obfuscated JavaScript malware package

Luke Hinds / Edward Thomson /
Mar 27, 2024
Continue Reading

CVEs: The emperor's old clothes

Luke Hinds /
Feb 21, 2024
Continue Reading

What is software provenance, and how can it keep your software secure?

Luke Hinds /
Jan 5, 2024
Continue Reading

Exploring Llama 2 on a Apple Mac M1/M2

Luke Hinds / Prachi Jadhav /
Jul 19, 2023
Continue Reading

Decoding Rekor: Understanding Sigstore's Transparency Log

Luke Hinds /
Jul 4, 2023
Continue Reading

Introducing Stacklok: Revolutionizing Open Source Security

Luke Hinds /
May 16, 2023
Continue Reading