Project Lightwell: Securing the open source supply chain
Red Hat's Project Lightwell is an initiative aimed at enhancing the security of the open source software supply chain. It focuses on providing tools and frameworks to help developers and organizations verify the integrity and provenance of open source components, thereby reducing the risk of supply chain attacks. The project seeks to establish trust and transparency in how open source code is built, distributed, and consumed.