[rb-general] blog post -- in-toto at rb-summit
Lukas Puehringer
lukas.puehringer at nyu.edu
Wed Jan 23 16:14:43 CET 2019
Dear all,
We just published a blog post about the Paris summit on our lab website:
https://ssl.engineering.nyu.edu/blog/2019-01-18-in-toto-paris
It is both a recap of the event, and a high-level introduction to how we
use in-toto to communicate and verify rebuild attestations (in Debian).
And it is also an invitation to get involved. We'd appreciate any help
on the following items:
- Package our relevant software for Debian [1], [2], [3]
- Deploy independent rebuilders [4]
- Explore ways of integration for other distros/projects
If you're interested please reach out to me/us!
Best,
Lukas
ps: I also wanted to say that I had a really good time at the summit.
Thanks for all the hard work and for being a warm and welcoming community!
[1] https://github.com/in-toto/in-toto
[2] https://github.com/in-toto/apt-transport-in-toto
[3] https://github.com/secure-systems-lab/securesystemslib
[4] https://salsa.debian.org/reproducible-builds/debian-rebuilder-setup
--
lukas.puehringer at nyu.edu
PGP fingerprint: 8BA6 9B87 D43B E294 F23E 8120 89A2 AD3C 07D9 62E8
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 874 bytes
Desc: OpenPGP digital signature
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20190123/6f4c5761/attachment.sig>
More information about the rb-general
mailing list