WhisperX tag archive

#in-toto

This page collects WhisperX intelligence signals tagged #in-toto. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-05-09 01:54:47 · GitHub Issues

1. in-toto-golang v0.11.0 Security Release Fixes Inconsistent Negation Behavior in Artifact Rules

A security-focused dependency update has been issued for in-toto-golang, advancing the module from v0.10.0 to v0.11.0 to address a vulnerability identified as GHSA-pmwq-pjrm-6p5r. The patch targets inconsistent negation behavior between the Go and Python implementations of the in-toto supply chain security framework, a...

The Lab · 2026-05-14 15:48:29 · GitHub Issues

2. Cross-Implementation Glob Pattern Bug Exposes Verification Gap in in-toto Supply Chain Framework

A semantic inconsistency between two in-toto reference implementations — in-toto-golang and in-toto-python — creates a verification gap that could undermine artifact rule enforcement across hybrid pipelines. Both libraries support glob patterns with character class negations in layout artifact rules, but they deploy in...