Resources

Stacklok Resources

Browse our latest blog posts, view videos from our team, and more.

Unlocking secure software distribution with Minder and GitHub Artifact Attestations

Jakub Hrozek / Adolfo "Puerco" García Veytia / Radoslav Dimitrov /
7 mins read
/
May 3, 2024

We’re excited to announce support in Minder for GitHub’s new Artifact Attestations feature, now in public beta. Artifact Attestations enables developers to easily publish attestations signed with the open source project sigstore.


Announcing the Proof-of-Diligence (PoD) algorithm: A method of modeling trust and maintainability in open source ecosystems

Luke Hinds / Pankaj Telang /
15 mins read
/
Apr 17, 2024

The OSS Trust Graph is an implementation of the Proof-of-Diligence algorithm created at Stacklok. Proof-of-Diligence (PoD) provides a robust mechanism to model trust, quality and maintainability in open source ecosystems. This blog post provides details on the reasoning behind the algorithm, how it is implemented, and how it can be used.


Announcing Minder and Trusty: Free-to-use tools to help developers and open source communities build safer software

5 mins read
/
Nov 7, 2023

We're excited to announce the launch of Minder and Trusty, two free-to-use tools that build on the power of the open source project Sigstore to help developers and open source communities keep their software safe.


Loading...

Dependency hijacking: Dissecting North Korea’s new wave of DeFi-themed open source attacks targeting developers

Poppaea McDermott /
Sep 10, 2024
Continue Reading

Securi-Taco Tuesday livestream recap: How code signing and Sigstore secure the software supply chain

Stacey Potter /
Sep 3, 2024
Continue Reading

Cross-platform RAT deployed by weaponized 'requests' clone

Luke Hinds / Poppaea McDermott /
Aug 30, 2024
Continue Reading

Now available in Trusty: Vulnerability and license information for open source packages

Megan Bruce /
Aug 27, 2024
Continue Reading

Open source licenses 101: What is the GNU GPL License?

Stacklok Editorial Team /
Aug 26, 2024
Continue Reading

Open source licenses 101: What is an MIT License?

Stacklok Editorial Team /
Aug 23, 2024
Continue Reading

5 risk factors of open source software beyond CVEs

Stacklok Editorial Team /
Aug 20, 2024
Continue Reading

Open source software licenses 101

Stacklok Editorial Team /
Aug 19, 2024
Continue Reading

Securi-Taco Tuesday Livestream Recap: Software Supply Chain 101 with Luke Hinds

Stacey Potter /
Aug 13, 2024
Continue Reading