<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Supply-Chain on Hi, I&#39;m Muhammad Amal</title>
    <link>https://muhammadamal.my.id/tags/supply-chain/</link>
    <description>Recent content in Supply-Chain on Hi, I&#39;m Muhammad Amal</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 24 Sep 2025 09:00:00 +0700</lastBuildDate>
    <atom:link href="https://muhammadamal.my.id/tags/supply-chain/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Supply Chain Security for AI Models, Signing and SBOM</title>
      <link>https://muhammadamal.my.id/blog/supply-chain-security-ai-models-signing-and-sbom/</link>
      <pubDate>Wed, 24 Sep 2025 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/supply-chain-security-ai-models-signing-and-sbom/</guid>
      <description>How to sign models, produce SBOMs that mean something for ML, and verify everything at runtime without slowing your team down.</description>
    </item>
    <item>
      <title>Container Image Signing with cosign and Sigstore in 2024</title>
      <link>https://muhammadamal.my.id/blog/container-image-signing-cosign-sigstore-2024/</link>
      <pubDate>Mon, 28 Oct 2024 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/container-image-signing-cosign-sigstore-2024/</guid>
      <description>A working guide to signing container images with cosign and Sigstore, including keyless signing and Kubernetes admission enforcement.</description>
    </item>
    <item>
      <title>SLSA v1.0 in Practice, Build Provenance Without Boiling the Ocean</title>
      <link>https://muhammadamal.my.id/blog/slsa-provenance-build-attestations/</link>
      <pubDate>Mon, 25 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/slsa-provenance-build-attestations/</guid>
      <description>Pragmatic SLSA v1.0 provenance with GitHub Actions and Cosign — what Level 2 actually delivers, and the operational lift to reach Level 3.</description>
    </item>
    <item>
      <title>SBOMs That Are Actually Useful, Syft, CycloneDX 1.5, and the Limits of Static Analysis</title>
      <link>https://muhammadamal.my.id/blog/sbom-syft-cyclonedx-pipeline/</link>
      <pubDate>Mon, 11 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/sbom-syft-cyclonedx-pipeline/</guid>
      <description>Producing accurate SBOMs with Syft and CycloneDX 1.5, the gaps you will not see, and how to attach them as signed attestations.</description>
    </item>
    <item>
      <title>Keyless Container Signing With Cosign 2.2, A Setup That Survives an Audit</title>
      <link>https://muhammadamal.my.id/blog/sigstore-cosign-keyless-signing/</link>
      <pubDate>Thu, 07 Sep 2023 09:00:00 +0700</pubDate>
      <guid>https://muhammadamal.my.id/blog/sigstore-cosign-keyless-signing/</guid>
      <description>Production-grade keyless container signing with Cosign 2.2 and Sigstore — the OIDC trust chain, Rekor verification, and air-gap caveats.</description>
    </item>
  </channel>
</rss>
