# attestation

Published articles for attestation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AMD Sends Out Linux Patches For Enabling SEV-TIO TDISP With PCIe 6.0

DevFeed: [AMD Sends Out Linux Patches For Enabling SEV-TIO TDISP With PCIe 6.0](<https://devfeed.tech/articles/amd-sends-out-linux-patches-for-enabling-sev-tio-tdisp-with-pcie-6-0-31406.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/AMD-SEV-TIO-TDISP-Linux-Patches>)

Author: Michael Larabel

Published: 2026-09-16T13:02:52Z

Content type: news

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [pcie](<https://devfeed.tech/topics/pcie.md>), [trusted-execution-environment](<https://devfeed.tech/topics/trusted-execution-environment.md>), [Confidential Computing](<https://devfeed.tech/topics/confidential-computing.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MERN](<https://devfeed.tech/topics/mern.md>)

Tags: [amd](<https://devfeed.tech/tags/amd.md>), [arm](<https://devfeed.tech/tags/arm.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [confidential-computing](<https://devfeed.tech/tags/confidential-computing.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [intel](<https://devfeed.tech/tags/intel.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [pcie](<https://devfeed.tech/tags/pcie.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [processors](<https://devfeed.tech/tags/processors.md>), [risc-v](<https://devfeed.tech/tags/risc-v.md>), [security](<https://devfeed.tech/tags/security.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>)

### AI overview

AMD submitted 17 Linux kernel patches to enable SEV-TIO TDISP for PCIe 6.0 and newer. The work is intended to secure direct I/O device assignment for confidential-computing environments, including AMD Secure Encrypted Virtualization guest VMs, and includes a common TEE Security Manager developed with Intel, Arm, and RISC-V.

### Source excerpt

The newest Linux kernel patches out of AMD for enhancing the upstream support with the new AMD EPYC 9006 "Venice" processors is for enabling SEV-TIO TDISP that is supported with PCI Express 6.0 and beyond...

## Securing a retail AI endpoint from abuse for virtual try on

DevFeed: [Securing a retail AI endpoint from abuse for virtual try on](<https://devfeed.tech/articles/securing-a-retail-ai-endpoint-from-abuse-for-virtual-try-on-16643.md>)

Original publisher: [Read original article](<https://firebase.blog/posts/2025/11/securing-ai-endpoints-from-abuse>)

Author: Alexander Nohe

Published: 2025-11-11T00:00:00Z

Content type: tutorial

Language: en

Sources: [Firebase Blog](<https://devfeed.tech/sources/firebase-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Firebase](<https://devfeed.tech/topics/firebase.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Code](<https://devfeed.tech/topics/code.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [app-check](<https://devfeed.tech/tags/app-check.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [code](<https://devfeed.tech/tags/code.md>), [curl](<https://devfeed.tech/tags/curl.md>), [devices](<https://devfeed.tech/tags/devices.md>), [firebase](<https://devfeed.tech/tags/firebase.md>), [generation](<https://devfeed.tech/tags/generation.md>), [genkit](<https://devfeed.tech/tags/genkit.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [image](<https://devfeed.tech/tags/image.md>), [model](<https://devfeed.tech/tags/model.md>), [rate-limiting](<https://devfeed.tech/tags/rate-limiting.md>), [retail](<https://devfeed.tech/tags/retail.md>), [server](<https://devfeed.tech/tags/server.md>), [token](<https://devfeed.tech/tags/token.md>)

### AI overview

A tutorial on protecting a Firebase AI endpoint for a virtual try-on application. It explains using App Check, replay-protected tokens, authentication, and rate limiting to reduce unauthorized access, replayed requests, and excessive generation costs.

### Source excerpt

Learn how to protect expensive AI features from abuse using Firebase App Check, Authentication, and rate limiting to ensure only legitimate users can access them.

## Building Hardware-Enforced Trust into Matter Devices with ESP-TEE

DevFeed: [Building Hardware-Enforced Trust into Matter Devices with ESP-TEE](<https://devfeed.tech/articles/building-hardware-enforced-trust-into-matter-devices-with-esp-tee-13724.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2025/09/matter_w_esp_tee_c6/>)

Author: John Lee

Published: 2025-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [Matter](<https://devfeed.tech/topics/matter.md>), [trusted-execution-environment](<https://devfeed.tech/topics/trusted-execution-environment.md>), [ESP32-C6](<https://devfeed.tech/topics/esp32-c6.md>), [RISC-V](<https://devfeed.tech/topics/riscv.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [esp-tee](<https://devfeed.tech/tags/esp-tee.md>), [esp32-c6](<https://devfeed.tech/tags/esp32-c6.md>), [iot](<https://devfeed.tech/tags/iot.md>), [matter](<https://devfeed.tech/tags/matter.md>), [risc-v](<https://devfeed.tech/tags/risc-v.md>), [security](<https://devfeed.tech/tags/security.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

This article explains how Espressif's ESP-TEE framework integrates with Matter on ESP32-C6 RISC-V SoCs. It describes hardware-isolated protection for device credentials, cryptographic operations, secure storage, OTA updates, attestation, and Matter DAC and NOC keys.

### Source excerpt

As security expectations rise globally - driven by region-specific cybersecurity regulations - safeguarding device credentials has become critical for IoT manufacturers. This article explains how the ESP-TEE framework integrates with Matter and demonstrates building secure products using the Espressif RISC-V SoCs, showcasing hardware-enforced security that can resist scalable remote software attacks.

## Laravel Cloud Achieves SOC 2 Type 2 Certification, Nightwatch and Forge Next

DevFeed: [Laravel Cloud Achieves SOC 2 Type 2 Certification, Nightwatch and Forge Next](<https://devfeed.tech/articles/laravel-cloud-achieves-soc-2-type-2-certification-nightwatch-and-forge-next-3756.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-achieves-soc-2-type-2-certification-nightwatch-and-forge-next>)

Author: André Valentin

Published: 2025-09-05T09:54:10Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [audits](<https://devfeed.tech/tags/audits.md>), [availability](<https://devfeed.tech/tags/availability.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [reports](<https://devfeed.tech/tags/reports.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [standards](<https://devfeed.tech/tags/standards.md>), [trust](<https://devfeed.tech/tags/trust.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Laravel Cloud achieved SOC 2 Type 2 certification for Security, Confidentiality, and Availability after completing its audit on July 31, 2025. The article explains the significance of SOC 2, contrasts Type 1 and Type 2 reports, and outlines planned SOC 2 audits for Nightwatch and Forge.

### Source excerpt

Laravel Cloud achieves SOC 2 Type 2 certification for Security, Confidentiality, and Availability. Read how Laravel's compliance roadmap includes Nightwatch and Forge SOC 2 audits.

## Workload Identity Meets Supply Chain Security: Teleport's Sigstore Integration

DevFeed: [Workload Identity Meets Supply Chain Security: Teleport's Sigstore Integration](<https://devfeed.tech/articles/workload-identity-meets-supply-chain-security-teleport-s-sigstore-integration-29974.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/workload-identity-meets-supply-chain-security/>)

Author: daniel.upton@goteleport.com (Dan Upton)

Published: 2025-06-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This article explains how Teleport integrates with Sigstore to strengthen software supply chain security for workload identity. It describes signing software artifacts and attestations, and explains Sigstore's keyless approach using single-use certificates tied to OIDC identities.

### Source excerpt

Learn how to use Teleport's integration with Sigstore to build supply chain security into your workload identity.

## Trusted Computing: The Role of Infrastructure IAM

DevFeed: [Trusted Computing: The Role of Infrastructure IAM](<https://devfeed.tech/articles/trusted-computing-the-role-of-infrastructure-iam-29949.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/trusted-computing-role-of-iam/>)

Author: info@thecyberhut.com (Simon Moffatt)

Published: 2025-02-26T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [trust](<https://devfeed.tech/topics/trust.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [frameworks](<https://devfeed.tech/tags/frameworks.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity](<https://devfeed.tech/tags/identity.md>), [identity-management](<https://devfeed.tech/tags/identity-management.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article examines how Infrastructure IAM and trusted computing extend trust beyond data and applications to the infrastructure that delivers services. It discusses zero trust, software attestation, cryptographic challenge-response authentication, and trusted platform modules, while noting the complexity and security risks of modern infrastructure.

### Source excerpt

Discover how Infrastructure IAM enhances trust in modern computing with zero trust principles and identity management for people, machines, and workloads.

## Announcing ESP-TEE Framework for ESP32-C6

DevFeed: [Announcing ESP-TEE Framework for ESP32-C6](<https://devfeed.tech/articles/announcing-esp-tee-framework-for-esp32-c6-13679.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2025/02/announcing-esp-tee/>)

Author: John Lee

Published: 2025-02-18T00:00:00Z

Content type: release

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [trusted-execution-environment](<https://devfeed.tech/topics/trusted-execution-environment.md>), [Security](<https://devfeed.tech/topics/security.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [RISC-V](<https://devfeed.tech/topics/riscv.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp-tee](<https://devfeed.tech/tags/esp-tee.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [esp32-c6](<https://devfeed.tech/tags/esp32-c6.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [freertos](<https://devfeed.tech/tags/freertos.md>), [iot](<https://devfeed.tech/tags/iot.md>), [ota](<https://devfeed.tech/tags/ota.md>), [risc-v](<https://devfeed.tech/tags/risc-v.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Espressif announces the availability of the ESP-TEE framework for ESP32-C6. The framework provides a hardware-enforced trusted execution environment that isolates sensitive computations and data from the main application, with features including secure storage, secure OTA updates, and attestation.

### Source excerpt

We are thrilled to announce the availability of the ESP-TEE (Trusted Execution Environment) framework for the ESP32-C6! Designed to enhance security on Espressif's SoCs, ESP-TEE enables a protected execution environment to safeguard sensitive information and operations. The Importance of the ESP-TEE# Security is paramount in the IoT landscape, where billions of devices exchange sensitive information daily.

## Matter: Improvements to Espressif DAC Provisioning Service

DevFeed: [Matter: Improvements to Espressif DAC Provisioning Service](<https://devfeed.tech/articles/matter-improvements-to-espressif-dac-provisioning-service-13915.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/matter-improvements-to-espressif-dac-provisioning-service/>)

Author: John Lee

Published: 2024-10-01T00:00:00Z

Content type: release

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [Matter](<https://devfeed.tech/topics/matter.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [devices](<https://devfeed.tech/tags/devices.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [iot](<https://devfeed.tech/tags/iot.md>), [matter](<https://devfeed.tech/tags/matter.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [trust](<https://devfeed.tech/tags/trust.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

Espressif describes updates to its Matter DAC provisioning service, including support for customer-factory manufacturing and secure delivery of Device Attestation Certificates for in-field devices upgrading to Matter.

### Source excerpt

Espressif's Secure Manufacturing Service, which was launched last year, has assisted many customers in simplifying their manufacturing. Since a year from launch, we worked with hundreds of customers and served millions of modules that were manufactured with this service.

## Apple already shipped attestation on the web, and we barely noticed

DevFeed: [Apple already shipped attestation on the web, and we barely noticed](<https://devfeed.tech/articles/apple-already-shipped-attestation-on-the-web-and-we-barely-noticed-19041.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/apple-private-access-tokens-attestation/>)

Author: HTTP Toolkit; Tim Perry

Published: 2023-07-25T14:00:00Z

Content type: opinion

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [Web](<https://devfeed.tech/topics/web.md>), [browser](<https://devfeed.tech/topics/browser.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>)

Tags: [apple](<https://devfeed.tech/tags/apple.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [browser](<https://devfeed.tech/tags/browser.md>), [browsers](<https://devfeed.tech/tags/browsers.md>), [chromium](<https://devfeed.tech/tags/chromium.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [http](<https://devfeed.tech/tags/http.md>), [ios](<https://devfeed.tech/tags/ios.md>), [macos](<https://devfeed.tech/tags/macos.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [server](<https://devfeed.tech/tags/server.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This opinion article examines Apple's Private Access Tokens, an attestation system integrated into macOS 13, iOS 16, and Safari. It explains how browsers, operating systems, attesters, and token issuers use HTTP challenges and signed tokens to verify that requests come from legitimate devices without disclosing the user's identity, while comparing the system with the proposed Web Environment Integrity model.

### Source excerpt

There's been a lot of concern recently about the Web Environment Integrity proposal, developed by a selection of authors from Google, and apparently being prototyped in Chromium. There's good reason for anger here (though I'm not sure yelling at people on GitHub is necessarily the best outlet). This proposal amounts to attestation on the web, limiting access to features or entire sites based on whether the client is approved by a trusted issuer. In practice, that will mean Apple, Microsoft & Google. Of course, Google isn't the first to think of this, but in fact they're not even the first to ship it. Apple already developed & deployed an extremely similar system last year, now integrated into MacOS 13, iOS 16 & Safari, called "Private Access Tokens": Private Access Tokens are powerful tools that prove when HTTP requests are coming from legitimate devices without disclosing someone's identity. The focus here is primarily on removing captchas, and as such it's been integrated into Cloudflare (discussed here) and Fastly (here) as a mechanism for recognizing 'real' clients without needing other captcha mechanisms. Fundamentally though, it's exactly the same concept: a way that web servers can demand your device prove it is a sufficiently 'legitimate' device before browsing the web. How do Private Access Tokens work? The mechanism is a fairly simple exchange over HTTP, handled by built-in browser APIs, which in turn integrate with operating system components to confirm that the browser & OS are 'legitimate' (the exact definition of that is left to the attester - i.e. Apple). The flow looks like this: A browser makes an HTTP request from a web server. The web server refuses the request, and returns an HTTP 401 response with a PrivateToken challenge: HTTP/1.1 401 Unauthorized WWW-Authenticate: PrivateToken challenge=<base64 challenge data>, token-key=<base64 public-key> (Newlines added for readability) The browser recognizes this, and sends parts of the challenge, in addit

## Reproducing Chainguard's reproducible image builds

DevFeed: [Reproducing Chainguard's reproducible image builds](<https://devfeed.tech/articles/reproducing-chainguard-s-reproducible-image-builds-13211.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/reproducing-chainguards-reproducible-image-builds>)

Published: 2023-07-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [locks](<https://devfeed.tech/tags/locks.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [secure-image](<https://devfeed.tech/tags/secure-image.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

A tutorial explaining how to reproduce a Chainguard Images build using cosign and apko. It describes locking image configurations and notes caveats involving tooling changes and withdrawn packages.

### Source excerpt

Learn how to reproduce a Chainguard Images build using cosign and apko.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.

## The role of attestations in a secure software supply chain

DevFeed: [The role of attestations in a secure software supply chain](<https://devfeed.tech/articles/the-role-of-attestations-in-a-secure-software-supply-chain-13269.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-role-of-attestations-in-a-secure-software-supply-chain>)

Published: 2023-04-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [Docker Verified Publisher](<https://devfeed.tech/topics/docker-verified-publisher.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-attestations](<https://devfeed.tech/tags/software-attestations.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article explains how attestations support software supply-chain policy enforcement. It describes attestations as signed claims from identified speakers about code or build results, allowing deployment systems to verify policy requirements without repeating expensive or impractical checks.

### Source excerpt

Chainguard Enforce enables policy enforcement using attestations. Learn how to use these principles to create and enforce secure supply chain policies.

## Matter Security Model

DevFeed: [Matter Security Model](<https://devfeed.tech/articles/matter-security-model-13917.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/matter-security-model/>)

Author: John Lee

Published: 2022-02-24T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [Matter](<https://devfeed.tech/topics/matter.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [controllers](<https://devfeed.tech/tags/controllers.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [devices](<https://devfeed.tech/tags/devices.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [iot](<https://devfeed.tech/tags/iot.md>), [ledger](<https://devfeed.tech/tags/ledger.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [matter](<https://devfeed.tech/tags/matter.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [process](<https://devfeed.tech/tags/process.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>), [storage](<https://devfeed.tech/tags/storage.md>), [trust](<https://devfeed.tech/tags/trust.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

An overview of Matter's security model, explaining how PKI, certificates, cryptography, and session establishment support trusted devices, trusted controllers, private communication, and data integrity. It also describes Matter's Device Attestation Certificate chain and the role of the Distributed Compliance Ledger.

### Source excerpt

Matter is a protocol designed with security and privacy in mind. Cryptography is widely adopted in Matter to ensure: - Trusted devices - Trusted controllers - Private communication In this post we will go through the Matter security model and investigate how these targets are accomplished in Matter. Introduction to Public Key Infrastructure# The Matter security model is based on Public Key Infrastructure(PKI), a cryptographic mechanism widely adopted in the Internet.

## New features in App Check beta

DevFeed: [New features in App Check beta](<https://devfeed.tech/articles/new-features-in-app-check-beta-16400.md>)

Original publisher: [Read original article](<https://firebase.blog/posts/2021/08/new-features-in-app-check-beta>)

Author: Tyler Crowe

Published: 2021-08-03T00:00:00Z

Content type: news

Language: en

Sources: [Firebase Blog](<https://devfeed.tech/sources/firebase-blog.md>)

Topics: [Firebase](<https://devfeed.tech/topics/firebase.md>), [Security](<https://devfeed.tech/topics/security.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [API](<https://devfeed.tech/topics/api.md>), [Cloud Functions](<https://devfeed.tech/topics/cloud-functions.md>), [Realtime Database](<https://devfeed.tech/topics/realtime-database.md>), [Cloud Run](<https://devfeed.tech/topics/cloud-run.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [admin-sdk](<https://devfeed.tech/tags/admin-sdk.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [app-attestation](<https://devfeed.tech/tags/app-attestation.md>), [app-check](<https://devfeed.tech/tags/app-check.md>), [apple](<https://devfeed.tech/tags/apple.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-functions](<https://devfeed.tech/tags/cloud-functions.md>), [cloud-run](<https://devfeed.tech/tags/cloud-run.md>), [firebase](<https://devfeed.tech/tags/firebase.md>), [launch](<https://devfeed.tech/tags/launch.md>), [news](<https://devfeed.tech/tags/news.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [realtime-database](<https://devfeed.tech/tags/realtime-database.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Firebase announces three additions to the App Check beta: iOS App Attest support, configurable token time-to-live values, and protection for non-Firebase backends. The article also explains how these features affect security, responsiveness, quota usage, and supported providers.

### Source excerpt

News, tutorials, and updates from the Firebase team.

## How Shopify Governs Containers at Scale with Grafeas and Kritis

DevFeed: [How Shopify Governs Containers at Scale with Grafeas and Kritis](<https://devfeed.tech/articles/how-shopify-governs-containers-at-scale-with-grafeas-and-kritis-1415.md>)

Original publisher: [Read original article](<https://shopify.engineering/how-shopify-governs-containers-at-scale-with-grafeas-and-kritis>)

Author: Jonathan jonathan pulsifer com

Published: 2017-10-12T15:02:00Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Shopify](<https://devfeed.tech/topics/shopify.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Google](<https://devfeed.tech/topics/google.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [audits](<https://devfeed.tech/tags/audits.md>), [ci](<https://devfeed.tech/tags/ci.md>), [container-registry](<https://devfeed.tech/tags/container-registry.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [google](<https://devfeed.tech/tags/google.md>), [identity](<https://devfeed.tech/tags/identity.md>), [images](<https://devfeed.tech/tags/images.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [operations](<https://devfeed.tech/tags/operations.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [policy](<https://devfeed.tech/tags/policy.md>), [production](<https://devfeed.tech/tags/production.md>), [registry](<https://devfeed.tech/tags/registry.md>), [security](<https://devfeed.tech/tags/security.md>), [shopify](<https://devfeed.tech/tags/shopify.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Shopify describes using Google's open source Grafeas to centralize metadata about container builds, images, packages, origins, deployments, and vulnerabilities. It also uses Kritis with Kubernetes to enforce real-time deployment policies based on signed attestations generated during CI.

### Source excerpt

Today, Google and its contributors launched Grafeas, an open source initiative to define a uniform way for auditing and governing the modern software supply chain. At Shopify, we're excited to be part of this announcement. Grafeas, or "scribe" in Greek, enables us to store critical software component metadata during our build and integration pipelines.