Supply Chain Security in CI: SBOMs, SLSA, and Sigstore
Software supply chain attacks target the build pipeline, not just the code. Defending against them requires visibility into dependencies, trusted build provenance, and artifact signing. SBOMs, SLSA...