A trusted build can faithfully ship malicious source
A perfectly secured pipeline, doing exactly what it should, will happily build and sign something malicious.
Provenance proves how an artefact was produced. It says nothing about whether what went in was good. The two questions are separate: is this what we built, and should we have built it. Signing answers the first, and it is regularly presented as answering both.
More on Software supply chain
- Dependency confusion exploits naming and resolutionSame name, wrong shelf
- Typosquatting attacks developer attentionThe eye test you take at 2am
- Lockfiles improve repeatability, not eternal safetyAlways the same tin
- Transitive dependencies enlarge unseen trustOne handshake, a hundred guests
- Maintainer compromise can use the normal release channelIt came by the usual van
- Build secrets should not become build artefactsDeleted on top, still underneath
