Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in / Register
Toggle navigation
Menu
Open sidebar
Shawn Webb
Slsa
Commits
6635577b
Unverified
Commit
6635577b
authored
Jan 04, 2022
by
Mark Lodato
Committed by
GitHub
Jan 04, 2022
Browse files
Merge pull request #252 from MarkLodato/typosquatting
Explain how SLSA can help with typosquatting.
parents
bb21d3e0
c506ccc0
Changes
1
Hide whitespace changes
Inline
Side-by-side
docs/_spec/v0.1/threats.md
View file @
6635577b
...
...
@@ -552,7 +552,10 @@ cryptographic signature is no longer valid.
*Threat:*
Register a package name that is similar looking to a popular package
and get users to use your malicious package instead of the benign one.
*Mitigation:*
**Outside the scope of SLSA.**
*Mitigation:*
**Mostly outside the scope of SLSA.**
That said, the requirement
to make the source available can be a mild deterrent, can aid investigation or
ad-hoc analysis, and can complement source-based typosquatting solutions.
<sup>
[[Verified history] and [Retained indefinitely] @ SLSA 3]
</sup>
</details>
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment