CASPR - Code Trust Audit Framework

By Ajit Hatti on 10 Aug 2022 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#secure-coding #secure-development #security-tools #code-review #sast #supply-chain-attack
Focus Areas: βš–οΈ Governance, Risk & Compliance , πŸ“¦ Software Supply Chain Security , πŸ” Application Security , βš™οΈ DevSecOps
This Tool Demo covers following tools where the speaker has contributed or authored
CASPR

Abstract

With CASPR, we are addressing the Supply Chain Attacks by Left Shifting the code signing process. CASPR aims to provide simple scripts and services architecture to ensure all code changes in an organization are signed by trusted keys; trustability of these keys should be instantly verifiable every time the code changes are consumed. It also makes the auditing and accountability of code-changes easier and cryptographically verifiable, leaving no scope for malicious actors to sneak in untrusted code at any point in the Software Development Life Cycle.