Best practices for managing and consuming public content and software in DevOps and cybersecurity
- Keep a copy of the software and supply chain artifacts as close as possible to the deployment location
- Automate builds and testing, and generate new supply chain artifacts
- Scan and patch all deployed software, even if it's archived for compliance
- Associate S-bombs and other claims with software versions in the registry
- Add annotations to improve information over time