Skip to content

Commit 651b91d

Browse files
committed
press mention
1 parent ba82090 commit 651b91d

File tree

2 files changed

+18
-4
lines changed

2 files changed

+18
-4
lines changed

personalpages/jcappos/index.htm

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -123,7 +123,7 @@ <h2 class="title">Contact</h2>
123123
<ul>
124124

125125
<li> <a href="https://theupdateframework.com/">TUF</a>, a
126-
graduated CNCF project which is used to secure software repositories both in
126+
graduated <a href="https://www.cncf.io/">CNCF</a> project which is used to secure software repositories both in
127127
the cloud and
128128
<a href="https://pyfound.blogspot.com/2020/10/key-generation-and-signing-ceremony-for.html">a</>
129129
<a href="https://blog.sigstore.dev/sigstore-bring-your-own-stuf-with-tuf-40febfd2badd">variety</a>
@@ -132,19 +132,25 @@ <h2 class="title">Contact</h2>
132132
<a href="https://www.linuxfoundation.org/press/announcing-openpubkey-project">use</a>
133133
<a href="https://engineering.nyu.edu/news/national-science-foundation-funds-nyu-tandon-school-engineering-project-safeguard-us-laws-and">cases</a>,
134134

135-
<li>
136-
<a href="https://in-toto.io/">in-toto</a>, an incubating level CNCF project,
135+
<li>
136+
<a href="https://in-toto.io/">in-toto</a>, a graduated level CNCF project,
137137
which is used by thousands of companies to secure the software supply chain
138138
(and is also being <a href="https://sbomit.dev/">extended to secure SBOMs</a>),
139139

140+
<li>
141+
<a href="https://gittuf.dev/">gittuf</a>, an incubating level
142+
<a href="https://openssf.org/">OpenSSF</a> project which secures users of Git
143+
repositories and forges
144+
(e.g., GitHub, GitLab, etc.) against supply chain attacks, and
145+
140146
<li> <a href="https://uptane.github.io/">Uptane</a>, a JDF project for securing
141147
automotive software updaters against nation-state actors, which is both a
142148
<a href="https://uptane.org/docs/standard/uptane-standard">JDF</a>
143149
and <a href="https://ieee-isto.org/">IEEE/ISTO</a> standard.
144150

145151
</ul>
146152

147-
He created and facilitates the Linux Foundation's TAG Security <a href="https://github.com/cncf/tag-security/tree/main/assessments">security assessment process</a> and wrote <a href="https://tag-security.cncf.io/community/assessments/Open_and_Secure.pdf">a book</a> about it.
153+
He created and facilitates the Linux Foundation's TAG Security and Compliance <a href="https://github.com/cncf/tag-security/tree/main/assessments">security assessment process</a> and wrote <a href="https://tag-security.cncf.io/community/assessments/Open_and_Secure.pdf">a book</a> about it.
148154
His open source <a href="/projects">research advances</a>
149155
are adopted into production use by Docker, git, Python, VMware, automobiles,
150156
Cloudflare, Microsoft, Amazon, Google, IBM, Digital Ocean, and major Linux

personalpages/jcappos/press.htm

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -727,6 +727,14 @@ <h3>Quick links</h3>
727727
</p>
728728

729729

730+
<p><strong>"Attestations: A new generation of signatures on PyPI"</strong>
731+
<a href="https://blog.trailofbits.com/2024/11/14/attestations-a-new-generation-of-signatures-on-pypi/">Article</a>
732+
(press coverage related to <a href="https://in-toto.io/">in-toto</a>) </br>
733+
The Trail of Bits Blog, November 2024.
734+
</p>
735+
736+
737+
730738
<p><strong>"How do video game companies like Game Freak keep getting hacked?"</strong>
731739
<a href="https://www.polygon.com/analysis/465967/pokemon-game-freak-nintendo-hack-leak">Article</a> </br>
732740
Polygon, October 2024.

0 commit comments

Comments
 (0)