Security●●Solid
I built a Cargo supply chain auditor using Claude and GitHub Actions
Tarball diffing plus Claude analysis catches build.rs backdoors cargo-audit misses.
Big BrainSolve My Problem
T-RN-R
302mo ago

From Witness/in-toto creators, keyless attestation blocks poisoned CI runs.
DevOps engineers, security teams, AI agent pipeline operators
Sigstore · in-toto · SLSA
Tarball diffing plus Claude analysis catches build.rs backdoors cargo-audit misses.
Ed25519-chained immutable deployment log—instant detection of tampering or reordering.
First real supply-chain defense for AI agent ecosystems; catches nation-state-grade payloads.
Speculative protocol for package quarantine without a reference implementation or registry buy-in.
NPM supply chain scanner competing against Socket, Snyk, and npm audit.
Maps hidden monopolies like Soitec wafers and Ajinomoto dielectric films.