mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
fix: README on trust
This commit is contained in:
@@ -17,6 +17,10 @@ See [example](https://safedep.io/malicious-npm-package-express-cookie-parser/)
|
|||||||
- Blocks malicious packages at install time
|
- Blocks malicious packages at install time
|
||||||
- No configuration required, just install and use
|
- No configuration required, just install and use
|
||||||
- Maintains package installation event log for transparency and audit trail
|
- Maintains package installation event log for transparency and audit trail
|
||||||
|
- Enforces least privilege and defense in depth using OS native sandboxing
|
||||||
|
|
||||||
|
PMG guarantees it's own artifact integrity using GitHub and npm attestations. Users can cryptographically prove that the binary they run
|
||||||
|
matches the source code they reviewed, eliminating the risk of tampered or malicious builds. See [why and how to trust PMG](docs/trust.md).
|
||||||
|
|
||||||
## PMG in Action
|
## PMG in Action
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -10,7 +10,7 @@ The assertion in [2] cannot be *implicit*. If so, it breaks the entire security
|
|||||||
## Security Goals
|
## Security Goals
|
||||||
|
|
||||||
- Adopt software supply chain security best practices so that PMG users can *verify* and only then trust PMG
|
- Adopt software supply chain security best practices so that PMG users can *verify* and only then trust PMG
|
||||||
- PMG is open source, built in public and reviewed by the community for trust in code
|
- PMG is open source, built in public and reviewed by the community for verifiable source of truth
|
||||||
- PMG leverages GitHub build attestation to verify the integrity of the PMG binary with source provenance
|
- PMG leverages GitHub build attestation to verify the integrity of the PMG binary with source provenance
|
||||||
- PMG npm package has build attestation to verify the integrity of the PMG binary and build environment with source provenance
|
- PMG npm package has build attestation to verify the integrity of the PMG binary and build environment with source provenance
|
||||||
- PMG security model is multi-layered without single point of failure
|
- PMG security model is multi-layered without single point of failure
|
||||||
@@ -48,7 +48,7 @@ Install verified binary for your platform:
|
|||||||
gh release download $RELEASE_TAG -R safedep/pmg --dir ./pmg-$RELEASE_TAG
|
gh release download $RELEASE_TAG -R safedep/pmg --dir ./pmg-$RELEASE_TAG
|
||||||
```
|
```
|
||||||
|
|
||||||
Install the platform specific binary from `./$pmg-$RELEASE_TAG`. To see binary specific attestation metadata, run:
|
Install the platform specific binary from `./pmg-$RELEASE_TAG`. To see binary specific attestation metadata, run:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
gh attestation verify pmg_Linux_x86_64.tar.gz -R safedep/pmg --format json
|
gh attestation verify pmg_Linux_x86_64.tar.gz -R safedep/pmg --format json
|
||||||
|
|||||||
Reference in New Issue
Block a user