World Congress 2024

Open Source Secure Software Supply Chain in action

July 18, 2024 13:30 – 14:00 Β· 30 min STAGE 9 (600)

What this session covers

More than 2/3 of application code is inherited from open source dependencies. It’s important to provide verified and attested code with provenance checks in the whole software development life cycle. Join talk where developers can learn and understand how to use software bill of materials (SBOM) and Vulnerability Exploitability eXchange (VEX) as part of the software supply chain for cloud-native applications. Sign commits, images, and pipelines to create a chain of trust for your open source components and transitive dependencies with open source projects.

Related talks at this congress

Open session

World Congress 2024

July 19, 2024 Β· 09:40–10:10

STAGE 6 (120)

Supply Chain Security - Strategies and Best Practices

Hendrik Ebbers

Creating the Hedera Hashgraph | Java Punk | Board Game Nerd ✌️

HE
Open session

World Congress 2024

July 19, 2024 Β· 11:40–12:10

Main Stage (5,000)

The Future of Open Source

Scott Chacon

SC
Open session

World Congress 2024

July 18, 2024 Β· 16:50–17:20

STAGE 2 (500)

How your .NET software supply chain is open to attack : and how to fix it

Andrei Epure

Software Engineering Manager at Sonar

Andrei Epure
Open session

World Congress 2024

July 18, 2024 Β· 11:30–12:00

STAGE 9 (600)

The internal developer platform and golden paths: Scaffolding for cloud-native development

Natale Vinto

Developer Advocate Global Lead

Natale Vinto
All sessions at this congress