Advertisement ยท 728 ร— 90

Posts by Carabiner Systems

Preview
SLSA End-to-End With AMPEL & Friends This guest post walks through a practical, end-to-end SLSA implementation using ๐Ÿ”ด๐ŸŸก๐ŸŸข AMPEL โ€” the Amazing Multipurpose Policy Engine (and L) โ€” along with other tools in the supply chain security ecosyst...

Read all about here :)
slsa.dev/blog/2025/10...

5 months ago 1 0 0 0

Then, we verify the #SBOM, a vulnerability scan, and apply signed #VEX documents to suppress any non-exploitable CVEs.

To round it all up, AMPEL issues a VSA for end-user consumption that ships with each artifact, showing how to verify the released binaries.

5 months ago 1 0 1 0

This time, the demo is a full SLSA end-to-end example. The post demonstrates how to leverage AMPEL to verify SLSA Build Track #attestations for the security level of a commit, check the provenance attestation of a builder image, and generate a VSA with the results, protecting the build process.

5 months ago 0 0 1 0

We've published a new ๐Ÿ”ด๐ŸŸก๐ŸŸข AMPEL case study on the SLSA Blog!

5 months ago 0 1 1 1

We would love to hear your thoughts and feedback, but only after celebrating with a couple of beers, cheers! ๐Ÿป

6 months ago 0 0 0 0

Shout out to @odd.computer for all their work securing open source and helping us operationalize OSS Rebuild with AMPEL ๐Ÿค—

6 months ago 1 0 1 0
Preview
GitHub - carabiner-dev/demo-npm-compromise: A sample npm app to verify compromised packages with Google's OSS Rebuild project A sample npm app to verify compromised packages with Google's OSS Rebuild project - carabiner-dev/demo-npm-compromise

AMPEL is Carbiner's flagship project, and to mark the release cut, we've published a PolicySet example and full demo/tutorial to protect projects from the recent npm credentials compromise with the help of Google's OSS Rebuild project. Check it out here:

github.com/carabiner-de...

6 months ago 1 0 1 0
Preview
GitHub - carabiner-dev/ampel: ๐Ÿ”ด๐ŸŸก๐ŸŸข The Amazing Multipurpose Policy Engine (and L) ๐Ÿ”ด๐ŸŸก๐ŸŸข The Amazing Multipurpose Policy Engine (and L) - carabiner-dev/ampel

We are proud to announce the second beta of ๐Ÿ”ด๐ŸŸก๐ŸŸข AMPEL, our software supply chain security policy engine! ๐Ÿฅณ

This release includes the final feature patches that were pending before the final release, plus a ton of improvements and bug fixes gathered during the beta.1 test

github.com/carabiner-de...

6 months ago 3 0 1 1
Preview
GitHub - carabiner-dev/signer: Easy digital signing library with support for sigstore and key pairs. Easy digital signing library with support for sigstore and key pairs. - carabiner-dev/signer

v0.2.0 of our signer library is out! This release ships with full support for DSSE signing and verification.

github.com/carabiner-de...

6 months ago 1 1 0 0
Advertisement
Post image

We've released v0.3.0 of bnd, our in-toto attestations multitool ๐ŸŽ‰

This release integrates ๐Ÿ”ด๐ŸŸก๐ŸŸข AMPEL's collectors, effectively turning bnd into a CLI to read and write attestations from the supported repositories.

Get it now: github.com/carabiner-de...

6 months ago 1 0 0 1