-

AlmaLinux and Home Assistant Now Independent Cryptographic Validators for Codenotary’s Free Service Enabling Supply Chain Security

Independent validation by large open source projects further strengthens Community Attestation Service

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain security, today announced it has added independent cryptographic validator nodes to its free and open source Community Attestation Service (CAS), providing another level of transparency, security and third-party verifiability of the data open-source projects notarize and authenticate using the service.

The AlmaLinux and Home Assistant projects are using the CAS independent validation to provide another layer of security on top of CAS’ code inventory and Software Bill of Materials (SBOM), helping to ensure no one has tampered with the data once it has been written. Here is the AlmaLinux validator and Home Assistant’s is here. Each instance is fully independent of the other.

“This independent validation service allows anyone, anywhere in the world to verify the integrity of the data that is stored in the CAS,” said Moshe Bar, co-founder and CEO of Codenotary. “It ensures that there is transparency and visibility into the backend of the service and that the notarization information stored is true and complete – so there is complete trust in the software being used. We encourage others to begin adding independent validators, as well.“

Backed by the open source immudb tamper-proof database, the CAS enables all open source software users the ability to generate a Software Bill of Materials that provides an inventory of its components.

The CAS traffic processes 1,200 transactions per second with a run-rate of about 1.2 million transactions per day. Millions of software assets (code, binaries, libraries, containers) have been notarized in the less than six months that the service has been available, presenting a major step forward in supply chain security posture for open source projects.

“CAS is a tremendous service to the open source community and at AlmaLinux we are deploying CAS as part of our build system,” said benny Vasquez, chair of the board of directors for AlmaLinux, the leading alternative to CentOS. “CAS, being totally free, is truly helping developers to secure the software they use, while enabling users to trust what they get.”

Home Assistant, provider of popular home automation software, uses the CAS to ensure the integrity of its software, as well as add-ons.

“Our content trust system uses CAS to enable both core and providers of third-party add-on extensions to Home Assistant to verify that the software delivered to our global community of users is secure, and what our users download and install is exactly the same as it was released by its creator and ensures nobody messed with it along the way. It helps to build a trustworthy IoT space,” said Pascal Vizeli, co-founder of Nabu Casa and core developer of Home Assistant.”

Anyone can secure the open source software they are using and generate SBOMs for free using Codenotary’s CAS.

About Codenotary

Codenotary brings easy to use trust and integrity into the software lifecycle by providing end-to-end cryptographically verifiable tracking and provenance for all artifacts, actions, and dependencies. Codenotary can be set up in minutes and can be fully integrated with modern CI/CD platforms. It is the only immutable and client-verifiable solution available that is capable of processing millions of transactions a second. With the Codenotary tamper-proof bill of materials, users can instantly identify untrusted components in their software builds. For more information, go to https://www.codenotary.com.

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

Codenotary


Release Summary
Codenotary announced it has added independent cryptographic validator nodes to its free and open source Community Attestation Service.
Release Versions

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

More News From Codenotary

Codenotary Accelerates Enterprise Adoption, Expands Into AI Agent Security and Autonomous Remediation

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced continued enterprise momentum alongside the launch of two new platforms, AgentMon and AgentX, that address security, observability and automation challenges associated with deploying AI agents in IT infrastructure. The company added 37 new enterprise customers over the past six months, including Kroger, Rakuten and Swiss Life. The strongest growth has been in defense and government sectors, where...

Codenotary Launches the First Enterprise Agentic Network Monitoring for Security, Performance and Cost Visibility

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced the launch of AgentMon, the first enterprise-grade monitoring designed specifically for agentic networks, providing organizations with real-time visibility into the security, performance and cost of AI-driven agents operating across the enterprise. As adoption of AI accelerates, agentic systems – semi-autonomous software agents that act on behalf of users and applications – are rapidly becoming em...

Codenotary Introduces First Autonomous Agentic Platform for Securing and Managing Linux Infrastructure and Securing Code

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced the availability of AgentX, the first autonomous platform to manage, secure, and protect large-scale Linux infrastructure in the cloud or on-premises through coordinated networks of AI agents. AgentX introduces a new approach to infrastructure operations by allowing distributed AI agents to collaborate, automating security enforcement, operational tasks, and lifecycle management while maintaining...
Back to Newsroom