Wednesday, January 21, 2026
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

GitHub Launches SLSA Build Level 3 Security with Full Code-to-Cloud Traceability

January 21, 2026
in Blockchain
Reading Time: 3 mins read
0 0
A A
0
Home Blockchain
Share on FacebookShare on Twitter


Jessie A Ellis
Jan 20, 2026 20:26

GitHub releases new APIs and artifact monitoring instruments enabling enterprises to hint software program from supply code via manufacturing deployment with cryptographic verification.

GitHub rolled out a big safety improve on January 20, 2026, introducing new APIs and tooling that permit improvement groups observe construct artifacts from supply code all the way in which to manufacturing environments—even when these artifacts dwell outdoors GitHub’s ecosystem.

The discharge addresses a persistent blind spot in enterprise software program safety: figuring out precisely what code is working in manufacturing and whether or not it matches what was truly constructed. With software program provide chain assaults turning into more and more refined, that visibility hole has grow to be a legal responsibility.

What’s Truly New

Three core capabilities make up the discharge. First, new REST API endpoints enable groups to create storage data (capturing the place artifacts dwell in package deal registries) and deployment data (monitoring the place code is working and related runtime dangers like web publicity or delicate information processing). These APIs work with exterior CI/CD instruments and cloud monitoring techniques, not simply GitHub Actions.

Second, a brand new “Linked artifacts view” within the group Packages tab consolidates all artifact information—attestations, storage areas, deployment historical past—right into a single dashboard. For groups utilizing GitHub’s artifact attestations, every artifact will get cryptographically sure to its supply repository and construct workflow.

Third, production-context filtering now works throughout Dependabot alerts, code scanning alerts, and safety campaigns. Groups can filter by artifact registry, deployment standing, and runtime danger, then mix these filters with EPSS and CVSS scores to prioritize what truly issues.

The SLSA Connection

The cryptographic binding piece is what allows SLSA Construct Stage 3 compliance—a provide chain safety framework that requires verifiable provenance for construct artifacts. Reasonably than trusting {that a} container picture got here from a particular commit, groups can mathematically confirm it. The system surfaces construct provenance attestations, attested SBOMs, and customized attestations via the artifact view.

Integration Companions at Launch

Microsoft Defender for Cloud (at present in public preview) handles deployment and runtime information integration. JFrog Artifactory offers storage and promotion context. Each supply native integrations requiring no extra configuration. For groups utilizing different tooling, the REST APIs settle for data from any supply.

GitHub’s attest-build-provenance motion can mechanically generate storage data when publishing artifacts, decreasing guide overhead for groups already within the GitHub Actions ecosystem.

Why This Issues for Enterprise Groups

Code-to-cloud traceability has grow to be a compliance requirement in regulated industries and a sensible necessity all over the place else. Realizing whether or not a flagged vulnerability truly made it to manufacturing—versus sitting in an unused department—basically modifications remediation priorities. Safety groups waste important time chasing vulnerabilities in code that by no means ships.

The timing aligns with broader trade strikes towards software program provide chain verification. With the characteristic now dwell, groups can begin constructing deployment data and testing the filtering capabilities instantly. Dialogue threads are lively in GitHub Group for groups working via implementation particulars.

Picture supply: Shutterstock



Source link

Tags: BuildCodetoCloudFullGitHubLaunchesLevelSecuritySLSATraceability
Previous Post

Bitcoin Below $90,000: Technicals Flash ‘Strong Sell’ as Geopolitical Fears Erase Monthly Gains

Next Post

XRP Bullish Divergence Shows The Next Direction That Price Is Headed In

Related Posts

Sei Labs Research Argues Stablecoins Turn Fed Into Global Retail Bank
Blockchain

Sei Labs Research Argues Stablecoins Turn Fed Into Global Retail Bank

January 20, 2026
Remote Deploys LangChain AI Agents to Automate Thousands of Customer Migrations
Blockchain

Remote Deploys LangChain AI Agents to Automate Thousands of Customer Migrations

January 20, 2026
HKMA Issues Fraud Alert Over Fake Social Media Accounts Impersonating Regulator
Blockchain

HKMA Issues Fraud Alert Over Fake Social Media Accounts Impersonating Regulator

January 20, 2026
APT Price Prediction: Targets $2.05-$2.10 by Week-End January 2026
Blockchain

APT Price Prediction: Targets $2.05-$2.10 by Week-End January 2026

January 20, 2026
Solana (SOL) PropAMMs Explained – How They Beat Traditional DEX Liquidity
Blockchain

Solana (SOL) PropAMMs Explained – How They Beat Traditional DEX Liquidity

January 20, 2026
BTC Consolidates Near $93K as ETF Inflows Hit $1.4B Weekly High
Blockchain

BTC Consolidates Near $93K as ETF Inflows Hit $1.4B Weekly High

January 19, 2026
Next Post
XRP Bullish Divergence Shows The Next Direction That Price Is Headed In

XRP Bullish Divergence Shows The Next Direction That Price Is Headed In

Sei Labs Research Argues Stablecoins Turn Fed Into Global Retail Bank

Sei Labs Research Argues Stablecoins Turn Fed Into Global Retail Bank

Gusto Unveils Global Stablecoin Payout Capabilities 

Gusto Unveils Global Stablecoin Payout Capabilities 

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In