Software Integrity & Product Trust
Follow the evidence chain from source and build systems through SBOM/VEX, signed release, deployment authorisation and provisioned product state.
Use this path when a signed or approved software artefact is being treated as sufficient evidence of trust. The decision is whether provenance, vulnerability state, deployment authority and provisioned product state can all be defended.
When Legitimate Engineering Workflows Can Carry Malicious Control Logic
See why the build environment itself belongs inside the product trust boundary.
A VEX Statement Is a Claim That Needs Evidence
Connect SBOM component presence to a scoped VEX exploitability claim backed by reviewable evidence.
A Valid Signature Does Not Make Vulnerable Firmware Safe
Separate cryptographic authenticity from vulnerability state and lifecycle patchability.
A Trusted Automotive Update Path Can Become the Malware Delivery Path
See why valid transport, identity and signatures still do not prove that a software artefact is authorised for a specific deployed product state.
How a Software-Defined Vehicle Could Inherit Compromise Before Delivery
Carry software integrity into the point where a software-defined product receives identity, code and operational authority.
When Compiling Becomes the Payload: The OpenPLC Supply Chain Trap
Revisit the build-trust problem in the longer audio discussion.
