March 10, 2022
in-toto has moved from the Cloud Native Computing Foundation (CNCF) Sandbox to the Incubator! Read the full announcement
here.
December 15, 2020
Tech Xplore released an
article warning about software supply chain attacks and describing in-toto.
December 12, 2020
The Linux Foundation received support to help advance several projects, including
in-toto!
June 3, 2019
Datadog has deployed TUF and in-toto into their pipeline! Read more
here.
June 1, 2019
Our paper “in-toto: providing farm-to-table security properties for bits and bytes” was accepted into USENIX ‘19. More information
here.
February 13, 2019
We’ve worked alongside with Control Plane to make a test deployment of
Kubesec using in-toto.
January 7, 2019
We released the first version of the
official in-toto Jenkins plugin. This provenance Agent will help you track and sign link metadata for any step within your pipeline in a secure and distributed way.
May 17, 2018
A
LWN article has been published, covering various supply chain security issues and their solutions, including grafeas, the update framework, and in-toto.
March 3, 2018
Our le-git-imate paper on improving the security of web-based Git repositories has been accepted at
ASIACCS 2018!
October 17, 2017
A fix to our git tag metadata tampering attack paper (
USENIX ‘16) has been included in the master branch of the pacman package manager and will be included in the next
release.
August 10, 2017
Lukas presented in-toto at Debian’s
Debconf 2017. You can watch the video of the talk
here.
January 17, 2017
A fix to our git tag metadata tampering vulnerability was merged into git’s master branch and will be available starting from
git v2.12. You can read more about it in our
USENIX ‘16 paper.
October 7, 2016
We are live! please check back soon for more updates.