Light Squares

Blog

Insights on software supply chain security, Confidential Computing, and building verifiable systems.

A look at cargo-vet in 2026

Cargo-vet requires audits of third-party Rust dependencies before they ship. We analyzed 408 open-source projects to measure adoption, audit workload, exemptions, and audit lag.

Read more →

Challenges with Reproducible Builds: scale and maintenance

Reproducible Builds mitigate trust gaps in the build step by making builds perfectly deterministic. However, they bring challenges that are often underestimated.

Read more →

Modern supply chain security needs scalable verifiability

Why trust alone cannot scale in modern software supply chains, and how Attestable Builds provide verifiability with minimal changes.

Read more →

From Cambridge to Taipei: presenting Attestable Builds at ACM CCS

We travelled to Taiwan to present our research on verifiable build attestation at ACM CCS 2025, one of the world's top security conferences.

Read more →