logo

S3C2 Summit 2025-09: Industry Secure Supply Chain Summit

Posted by jruohonen |2 hours ago |1 comments

jruohonen 2 hours ago

And the accompanying:

https://arxiv.org/abs/2605.29140

Some good takes on new (and old) ideas to consider.

I don't know what should or could be done, but maybe people will revert back to using only distribution-shipped packages. There was a good argument from Ubuntu people about this a while back:

https://news.ycombinator.com/item?id=47585172