shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

284
active users

#gittuf

0 posts0 participants0 posts today
Risotto Bias<p>other than <span class="h-card" translate="no"><a href="https://social.rust-lang.org/@rust" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>rust</span></a></span> 's "we don't want TUF but we want to start with almost TUF, extend it, and accidentally build TUF but different*"[1][2]...</p><p>...I kinda haven't seen any good pro/con/alternative docs on things besides <a href="https://tech.lgbt/tags/TUF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TUF</span></a> or <a href="https://tech.lgbt/tags/sigstore" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sigstore</span></a> (okay, in-toto is... different. as is <a href="https://tech.lgbt/tags/gittuf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gittuf</span></a>) </p><p>heck, Python adopted it.</p><p>Golang's metadata/proxy stuff is slightly different...</p><p>I guess what I'm saying is there's opportunity for a cool writeup on package and language supply chain security landscapes.</p><p>lighter threat models, the difference between git, language, OS, and cluster threat models,</p><p><a href="https://tech.lgbt/tags/trdl" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>trdl</span></a> <a href="https://tech.lgbt/tags/automotivelinux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>automotivelinux</span></a> <a href="https://tech.lgbt/tags/rustlang" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rustlang</span></a> <a href="https://tech.lgbt/tags/InToto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InToto</span></a> <a href="https://tech.lgbt/tags/opa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opa</span></a> </p><p>[1] Rust <a href="https://foundation.rust-lang.org/news/2023-12-21-improving-supply-chain-security/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">foundation.rust-lang.org/news/</span><span class="invisible">2023-12-21-improving-supply-chain-security/</span></a><br>[2] Rust <a href="https://github.com/rust-lang/rfcs/pull/2474" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/rust-lang/rfcs/pull</span><span class="invisible">/2474</span></a><br>[3] PyPi <a href="https://peps.python.org/pep-0458/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">peps.python.org/pep-0458/</span><span class="invisible"></span></a><br>[4] Ocaml <a href="https://opam.ocaml.org/blog/Signing-the-opam-repository/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">opam.ocaml.org/blog/Signing-th</span><span class="invisible">e-opam-repository/</span></a><br>[5] <a href="https://github.com/php-tuf/php-tuf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/php-tuf/php-tuf</span><span class="invisible"></span></a> (old not official)<br>[6] Haskell <a href="https://www.well-typed.com/blog/2015/04/improving-hackage-security/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">well-typed.com/blog/2015/04/im</span><span class="invisible">proving-hackage-security/</span></a><br>[7] *gestures wildly at sigstore/docker/kubernetes*</p><p>*(in the accent of zefrank1 of "true facts about..") "as rust developers are want to do. same same, but different."</p>