Skip to main content

Resources

Find your next step.

Understand the approach. See how it fits your team. Get it running.

Research and standards

The work behind our approach.

Publications our team helped shape, and the open specification our tooling builds on. Read the original sources and see where the ideas apply.

First page of NIST SP 800-204DPublication cover

NIST · Special Publication · 2024

NIST SP 800-204D

Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines

A practical foundation for bringing supply chain security into build and delivery workflows.

Co-author

Frederick Kautz co-authored this publication with Ramaswamy Chandramouli and Santiago Torres-Arias. NIST lists his affiliation as TestifySec.

View the source attribution ↗
First page of Software Supply Chain Best Practices v2Repository PDF · publication date placeholder

CNCF TAG Security · Community guidance · v2 repository edition

Software Supply Chain Best Practices v2

Updated guidance for the people building and consuming software.

Covers attestation generation, distribution, verification and storage, including Witness and Archivista examples.

Original-author credit

Version 2 credits the original white paper authors alongside its update authors. Cole Kennedy is named in the version 1 contribution record.

View the source attribution ↗
First page of Secure Software FactoryPublication cover

CNCF TAG Security · Reference architecture

Secure Software Factory

An architecture for collecting and verifying software provenance.

Shows how workflow infrastructure, evidence collection, policy, and verification fit together.

Authorship and acknowledgements

Cole Kennedy is a named author in the web edition. Frederick Kautz is acknowledged for input and feedback.

View the source attribution ↗

Looking for company resources?