Sign in

Carabiner Systems

@carabiner.dev
11 followers 2 following 10 posts

At Carabiner Systems we're busy building the connective tissue that will bind the supply chain security ecosystem 🔗

PostsRepliesMedia
Carabiner Systems @carabiner.dev · 23/10/2025
Read all about here :) slsa.dev/blog/2025/10...
slsa.dev
SLSA End-to-End With AMPEL & Friends
This guest post walks through a practical, end-to-end SLSA implementation using 🔴🟡🟢 AMPEL — the Amazing Multipurpose Policy Engine (and L) — along with other tools in the supply chain security ecosyst...
010
Carabiner Systems @carabiner.dev · 23/10/2025
Then, we verify the #SBOM, a vulnerability scan, and apply signed #VEX documents to suppress any non-exploitable CVEs. To round it all up, AMPEL issues a VSA for end-user consumption that ships with each artifact, showing how to verify the released binaries.
110
Carabiner Systems @carabiner.dev · 23/10/2025
This time, the demo is a full SLSA end-to-end example. The post demonstrates how to leverage AMPEL to verify SLSA Build Track #attestations for the security level of a commit, check the provenance attestation of a builder image, and generate a VSA with the results, protecting the build process.
100
Carabiner Systems @carabiner.dev · 23/10/2025
We've published a new 🔴🟡🟢 AMPEL case study on the SLSA Blog!
101
Carabiner Systems @carabiner.dev · 24/09/2025
We would love to hear your thoughts and feedback, but only after celebrating with a couple of beers, cheers! 🍻
000
Carabiner Systems @carabiner.dev · 24/09/2025
Shout out to @odd.computer for all their work securing open source and helping us operationalize OSS Rebuild with AMPEL 🤗
110
Carabiner Systems @carabiner.dev · 24/09/2025
AMPEL is Carbiner's flagship project, and to mark the release cut, we've published a PolicySet example and full demo/tutorial to protect projects from the recent npm credentials compromise with the help of Google's OSS Rebuild project. Check it out here: github.com/carabiner-de...
github.com
GitHub - carabiner-dev/demo-npm-compromise: A sample npm app to verify compromised packages with Google's OSS Rebuild project
A sample npm app to verify compromised packages with Google's OSS Rebuild project - carabiner-dev/demo-npm-compromise
110
Carabiner Systems @carabiner.dev · 24/09/2025
We are proud to announce the second beta of 🔴🟡🟢 AMPEL, our software supply chain security policy engine! 🥳 This release includes the final feature patches that were pending before the final release, plus a ton of improvements and bug fixes gathered during the beta.1 test github.com/carabiner-de...
github.com
GitHub - carabiner-dev/ampel: 🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L)
🔴🟡🟢 The Amazing Multipurpose Policy Engine (and L) - carabiner-dev/ampel
130
Carabiner Systems @carabiner.dev · 11/09/2025
v0.2.0 of our signer library is out! This release ships with full support for DSSE signing and verification. github.com/carabiner-de...
github.com
GitHub - carabiner-dev/signer: Easy digital signing library with support for sigstore and key pairs.
Easy digital signing library with support for sigstore and key pairs. - carabiner-dev/signer
011
Carabiner Systems @carabiner.dev · 05/09/2025
We've released v0.3.0 of bnd, our in-toto attestations multitool 🎉 This release integrates 🔴🟡🟢 AMPEL's collectors, effectively turning bnd into a CLI to read and write attestations from the supported repositories. Get it now: github.com/carabiner-de...
010