-

AlmaLinux and Home Assistant Now Independent Cryptographic Validators for Codenotary’s Free Service Enabling Supply Chain Security

Independent validation by large open source projects further strengthens Community Attestation Service

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain security, today announced it has added independent cryptographic validator nodes to its free and open source Community Attestation Service (CAS), providing another level of transparency, security and third-party verifiability of the data open-source projects notarize and authenticate using the service.

The AlmaLinux and Home Assistant projects are using the CAS independent validation to provide another layer of security on top of CAS’ code inventory and Software Bill of Materials (SBOM), helping to ensure no one has tampered with the data once it has been written. Here is the AlmaLinux validator and Home Assistant’s is here. Each instance is fully independent of the other.

“This independent validation service allows anyone, anywhere in the world to verify the integrity of the data that is stored in the CAS,” said Moshe Bar, co-founder and CEO of Codenotary. “It ensures that there is transparency and visibility into the backend of the service and that the notarization information stored is true and complete – so there is complete trust in the software being used. We encourage others to begin adding independent validators, as well.“

Backed by the open source immudb tamper-proof database, the CAS enables all open source software users the ability to generate a Software Bill of Materials that provides an inventory of its components.

The CAS traffic processes 1,200 transactions per second with a run-rate of about 1.2 million transactions per day. Millions of software assets (code, binaries, libraries, containers) have been notarized in the less than six months that the service has been available, presenting a major step forward in supply chain security posture for open source projects.

“CAS is a tremendous service to the open source community and at AlmaLinux we are deploying CAS as part of our build system,” said benny Vasquez, chair of the board of directors for AlmaLinux, the leading alternative to CentOS. “CAS, being totally free, is truly helping developers to secure the software they use, while enabling users to trust what they get.”

Home Assistant, provider of popular home automation software, uses the CAS to ensure the integrity of its software, as well as add-ons.

“Our content trust system uses CAS to enable both core and providers of third-party add-on extensions to Home Assistant to verify that the software delivered to our global community of users is secure, and what our users download and install is exactly the same as it was released by its creator and ensures nobody messed with it along the way. It helps to build a trustworthy IoT space,” said Pascal Vizeli, co-founder of Nabu Casa and core developer of Home Assistant.”

Anyone can secure the open source software they are using and generate SBOMs for free using Codenotary’s CAS.

About Codenotary

Codenotary brings easy to use trust and integrity into the software lifecycle by providing end-to-end cryptographically verifiable tracking and provenance for all artifacts, actions, and dependencies. Codenotary can be set up in minutes and can be fully integrated with modern CI/CD platforms. It is the only immutable and client-verifiable solution available that is capable of processing millions of transactions a second. With the Codenotary tamper-proof bill of materials, users can instantly identify untrusted components in their software builds. For more information, go to https://www.codenotary.com.

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

Codenotary


Release Summary
Codenotary announced it has added independent cryptographic validator nodes to its free and open source Community Attestation Service.
Release Versions

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

More News From Codenotary

immudb Gains Market Momentum as the Leading Immutable Database for Secure and Tamper-Proof Data Storage

HOUSTON--(BUSINESS WIRE)--immudb, the world’s fastest immutable database, is gaining significant traction across industries as organizations seek enhanced security, integrity, and verifiability for their data. With a growing adoption in sectors like finance, healthcare, defense, and government, immudb has over the last several years become a mainstay for businesses that require real-time, tamper-proof data storage. Developed by Codenotary Inc and designed as a high-performance, zero-trust datab...

Codenotary Closes 2024 With Record Sales and Profit Growth

HOUSTON--(BUSINESS WIRE)--Codenotary Inc., a global leader in software supply chain security, reports record sales growth for the fiscal year 2024, driven by the widespread adoption of its flagship product, Trustcenter, and the launch of the new product Guardian. Together, these products provide a comprehensive solution for securing the full lifecycle secure application development and deployment, ensuring unparalleled levels of trust and resilience. With a surge in sales across critical sector...

Codenotary Announces First Half of FY 2024 With Record Sales Growth

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced that the company has closed the first half of 2024 with record sales and strong expansion into the financial services and government segments, as well as into the defense vertical with best-in-class supply chain security platform, Trustcenter. “The first half of 2024 saw Codenotary close several multi-year agreements with world-class customers in financial and government sectors. We grew equally i...
Back to Newsroom