<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Blog on in-toto</title><link>https://in-toto.io/blog/</link><description>Recent content in Blog on in-toto</description><generator>Hugo</generator><language>en-US</language><atom:link href="https://in-toto.io/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Security Audit '23</title><link>https://in-toto.io/blog/2023/security-audit/</link><pubDate>Thu, 11 May 2023 00:00:00 +0000</pubDate><guid>https://in-toto.io/blog/2023/security-audit/</guid><description>&lt;p&gt;We are excited to announce completion of a source code audit of the in-toto
Python and Go implementations along with an architectural review of the
specification. The audit was ordered by the Open Source Technology Improvement
Fund (OSTIF) and conducted by X41 D-Sec GmbH over the course of three weeks in
February 2023.&lt;/p&gt;
&lt;h2 id="motivation"&gt;Motivation&lt;a class="td-heading-self-link" href="#motivation" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;While in-toto has previously undergone a security review by the CNCF’s
TAG-Security, it had not been formally audited thus far. The in-toto
implementations are currently used in production and the Python reference
implementation reached v1.0 maturity in late 2020. The Go implementation has
been the experimental testbed for several new features including the in-toto
Attestation Framework. We decided in our roadmap that it is time to release v1.0
of the specification and to apply for graduation at the CNCF. To formally
underline our confidence in the specification we initiated the in-toto audit.&lt;/p&gt;</description></item></channel></rss>