HN user

migmartri

146 karma

Giving your software supply chain superpowers at chainloop.dev

miguel at chainloop.dev

Posts10
Comments11
View on HN

For some reason, the act of choosing a plugin mechanism for our new project has been presented in my head a dilemma. Not a clear winner between the built-in stuff (plugin stdlib), the boring but battle tested option (Hashicorp go-plugin [1]) and the new exciting shiny ("future proof?") object web assembly plugins [2]

I ended up choosing the "traditional" Hashicorp library but any feedback, or comments on why you might think I am making a terrible mistake would be appreciated :)

[1] https://github.com/hashicorp/go-plugin [2] https://github.com/WebAssembly/WASI/blob/snapshot-01/phases/...

Chainloop is not designed nor implemented with that centralization concept in mind.

It is meant to run as any other OSS infrastructure piece in your Software Supply Chain. The source of truth that we describe, it's about providing organizations with a single mechanism to define, ingest and route metadata and artifacts to their final destination (i.e artifactory, OCI registry, ...)

hi, Chainloop developer here.

I completely agree with your comment. We might be doing a poor job at explaining what Chainloop is compared to Sigstore.

Chainloop is built on top of Sigstore's (among from others) great OSS building blocks. We use cosign, in-toto and DSSE for generation or OCI for storing the attestations. It's true that today the signing is done using a asymmetric cosign key at the moment of the attestation crafting but we have plans on implementing keyless/identity signing and verifying using Sigstore fulcio+rekor.

Message in their customers dashboard.

"Dear Customers,

We're experiencing a DDoS attack on our DNSv2 system at the moment - this means that any domains that are using DNSv2 or FreeDNS nameservers may experience intermittent availability issues. We are currently in the process of mitigating the attack and are working hard to ensure a quick resolution. We sincerely apologize for the inconvenience caused."

I thought that rubystack was focused to give the users everything they need to start working with rails avoiding environment setup as well.

Sorry but I am trying to see the difference but I am not sure if I can.

So then the difference is some kind of friendly/more advanced installation interface and an easy way to get started installing less "stuff" than rubystack does?