Skip to content

Commit 70fe091

Browse files
Update master-thesis.md
1 parent e6bab92 commit 70fe091

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

master-thesis.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,11 @@ title: Open Master Thesis Topics in Project Chains
66

77
Project Chains hosts master's students for their theses, here are available topics. See [main page](/) for completed theses.
88

9+
<h3 >Trust Assumptions and Threats in Build Attestation System</h3>
10+
Contact: Larissa Schmid
11+
<p>Description:
12+
Build attestations are cryptographically verifiable statements that describe how, when, and by whom a software artifact was produced. They are used for strengthening software supply chain security by ensuring that binaries and container images can be traced back to a documented build process. While standards like SLSA and tools such as Sigstore, Tekton Chains, and GitHub's native attestations promise to ensure trust in build outputs, there is no systematic assessment of their capabilities and limitations. This thesis will examine which trust assumptions different build attestation systems make, what attacker models they use, and how well current implementations satisfy their security goals. The work should evaluate potential attack vectors and propose recommendations for more robust, verifiable provenance. </p>
13+
914
### Empirical study of vulnerability tracking processes in vulnerability reports
1015
Contact: Yekatierina Churakova
1116
<p>Description:

0 commit comments

Comments
 (0)