#attestation
Tagged “attestation”
2 articlesSecurity & supply chain
The SBOM you can trust is the one your build actually made
Docker published a guide arguing that SBOMs generated at build time beat post-build scans on completeness, accuracy and freshness. The distinction quietly changes what a CI pipeline is on the hook for.
Jul 8, 2026 · Tomás VegaSecurity & supply chainGoogle, Microsoft and OpenAI route their AI 'trust layer' work through the Linux Foundation
Three of the largest AI vendors are aligning on a Linux Foundation–housed effort to build a shared trust layer for AI systems. For platform teams the read is operational: artefact provenance for models and agents is about to ride the same plumbing that already carries binary attestation.
Jun 18, 2026 · Maya Okonkwo