The Artifact is Free, Assurance is the Product: Trust in Software Supply Chains

rseroter · x · 2026-08-14

A RedMonk article explores how modern software registries (like npm, PyPI) are evolving from mere distribution systems into policy engines and trust services. Following a wave of supply chain attacks, platforms are shifting towards short-lived credentials tied to verified build pipelines.

The author notes that while underlying software artifacts (like hardened images) remain free, a new market pattern is emerging: the artifact is free, assurance is the product. Vendors are now charging for trust assurances such as provenance, SLAs, and vulnerability protection, though they stop short of offering behavioral guarantees.

Original post →

More from coding & agent

coding & agent channel →