<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>GUAC Open Source — Host Boards</title>
        <link>https://hostboards.com/index.php?p=/</link>
        <pubDate>Wed, 29 Jul 2026 17:42:37 +0000</pubDate>
        <language>en</language>
            <description>GUAC Open Source — Host Boards</description>
    <atom:link href="https://hostboards.com/index.php?p=/discussions/tagged/guac-open-source/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Google Launches GUAC Open Source Project to Secure Software Supply Chain</title>
        <link>https://hostboards.com/index.php?p=/discussion/5882/google-launches-guac-open-source-project-to-secure-software-supply-chain</link>
        <pubDate>Sat, 22 Oct 2022 14:11:42 +0000</pubDate>
        <category>Coding Languages</category>
        <dc:creator>DeluxeNames</dc:creator>
        <guid isPermaLink="false">5882@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Google on Thursday announced that it's seeking contributors to a new open source initiative called Graph for Understanding Artifact Composition, also known as GUAC, as part of its ongoing efforts to beef up the software supply chain.</p>

<p>"GUAC addresses a need created by the burgeoning efforts across the ecosystem to generate software build, security, and dependency metadata," Brandon Lum, Mihai Maruseac, and Isaac Hepworth of Google said in a post shared with The Hacker News.</p>

<p>"GUAC is meant to democratize the availability of this security information by making it freely accessible and useful for every organization, not just those with enterprise-scale security and IT funding."</p>

<p>CyberSecurity<br />
Software supply chain has emerged a lucrative attack vector for threat actors, wherein exploiting just one weakness -- as seen in the case of SolarWinds and Log4Shell -- opens a pathway long enough to traverse down the supply chain and steal sensitive data, plant malware, and take control of systems belonging to downstream customers.</p>

<p>Google, last year, released a framework called SLSA (short for Supply chain Levels for Software Artifacts) that aims to ensure the integrity of software packages and prevent unauthorized modifications.</p>

<p>It has also launched an updated version of Security Scorecards, which identifies the risk third-party dependencies can introduce to a project, allowing developers to make informed decisions about accepting vulnerable code or considering other alternatives.</p>

<p>"[GUAC] aims to satisfy the use case of being a monitor for public supply chain and security documents as well as for internal use by organizations to query information about artifacts that they use," the internet giant noted.</p>

<p>Source: <br />
<a href="https://thehackernews.com/2022/10/google-launches-guac-open-source.html" rel="nofollow">https://thehackernews.com/2022/10/google-launches-guac-open-source.html</a></p>
]]>
        </description>
    </item>
<div class="SFBox SFVCBox"><span>Online Since</span>April 2004</div><div class="SFBox SFVCBox"><span>Total Views</span>3.1M</div><div class="SFBox SFUBox"><span>Total Users</span>3.7M</div><div class="SFBox SFTBox"><span>Total Topics</span>7.8K</div><div class="SFBox SFPBox"><span>Post Count</span>33.3K</div>   </channel>
</rss>
