Supply chain security for LLM artifacts using Sigstore, in-toto, and SLSA frameworks. Generates signed attestations for model weights, training data, and inference outputs.
There have been a lot of supply-chain attacks on projects, by way of creating fake or tainted node.js packages. The base for this attack is complete anonimity without even signature for the package...
An open standard and zero-dependency reference toolkit that produces an authorization receipt: offline-verifiable proof that a named human approved an exact, irreversible AI-agent action before it ...
Elda is a Unix/Linux system package manager written in Rust. It explores signed remotes, explicit installed-state ledgers, rollback-aware transactions, package recipes, source and binary lanes, and...