Topic mix

Software supply chain security

18 moments from 16 videos · 55:34 min total

Securing software pipelines is critical to modern development. This playlist brings together essential moments from expert talks on managing open-source dependencies and verifying third-party packages.

How your .NET software supply chain is open to attack : and how to fix it
Play section Understanding software supply chain threats and security risks
Understanding software supply chain threats and security risks thumbnail

Understanding software supply chain threats and security risks

The software supply chain encompasses all build tools and dependencies, which are increasingly targeted by data exfiltration attacks.

Play section Essential best practices for securing nuget package configurations
Essential best practices for securing nuget package configurations thumbnail

Essential best practices for securing nuget package configurations

Engineering teams prevent supply chain attacks by reserving package prefixes, signing binaries, clearing system defaults, and inspecting new targets.

Building Trust Through Private and Verifiable AI
Play section Securing contextual storage and proving verifiable transparency
Securing contextual storage and proving verifiable transparency thumbnail

Securing contextual storage and proving verifiable transparency

User-controlled encryption keys secure stored documents while hardware vendor attestation enables independent software assurance verification.

Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?
Play section Mapping the complete software supply chain attack surface
Mapping the complete software supply chain attack surface thumbnail

Mapping the complete software supply chain attack surface

Why comprehensive security requires validating build environments and commercial dependencies beyond open source component scanning.

Securing your application software supply-chain
Play section Integrating security across the application development lifecycle
Integrating security across the application development lifecycle thumbnail

Integrating security across the application development lifecycle

Adopting a progressive approach to threat modeling supply chains ensures that security practices scale with complex modern workflows.

Play section Adopting the SLSA framework for supply chain maturity
Adopting the SLSA framework for supply chain maturity thumbnail

Adopting the SLSA framework for supply chain maturity

Progressively implementing supply chain levels enables teams to automate verifiable provenance without manually juggling cryptographic keys.

Security Pitfalls for Software Engineers
Play section Mitigating risks from supply chain attacks and vulnerable libraries
Mitigating risks from supply chain attacks and vulnerable libraries thumbnail

Mitigating risks from supply chain attacks and vulnerable libraries

Exploited open source dependencies like Log4j highlight the absolute necessity for aggressive software supply chain oversight.

Making Teaching Code Less Academic and More Market-Ready - Peter Ruppel
Play section Implementing preventative cybersecurity to mitigate software supply chain risks
Implementing preventative cybersecurity to mitigate software supply chain risks thumbnail

Implementing preventative cybersecurity to mitigate software supply chain risks

Teams must actively prioritize access control and foundational security checks instead of relying on delayed patching protocols.

Building on Open Source: The New Product Playbook
Play section Gaining software supply chain visibility through upstream engagement
Gaining software supply chain visibility through upstream engagement thumbnail

Gaining software supply chain visibility through upstream engagement

Participating directly in upstream development eliminates vendor bottlenecks and secures control over essential infrastructure dependencies.

The AI Security Survival Guide: Practical Advice for Stressed-Out Developers
Play section Artificial intelligence components in the software supply chain
Artificial intelligence components in the software supply chain thumbnail

Artificial intelligence components in the software supply chain

Integrating language models introduces inherited vulnerabilities into development workflows regardless of direct implementation.

Real-World Security for Busy Developers
Play section Evaluating supply chain risk through automated dependency reviews
Evaluating supply chain risk through automated dependency reviews thumbnail

Evaluating supply chain risk through automated dependency reviews

Checking new package manifests against global advisory databases during branch merges prevents the introduction of critical software supply chain vulnerabilities.

An alternative approach to digital sovereignty: Confidential Computing
Play section Securing digital supply chains using isolated build environments
Securing digital supply chains using isolated build environments thumbnail

Securing digital supply chains using isolated build environments

Generating provenance proofs natively inside secure hardware guarantees the integrity of continuous software bills of materials.

How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski
Play section Avoiding supply chain risks within standard software dependencies
Avoiding supply chain risks within standard software dependencies thumbnail

Avoiding supply chain risks within standard software dependencies

Recognizing hidden threats located inside widely adopted package managers and binary compilation tools.

Overcome your trust issues! In a world of fake data, Data Provenance FTW
Play section Vulnerabilities within the cyber software supply chain
Vulnerabilities within the cyber software supply chain thumbnail

Vulnerabilities within the cyber software supply chain

Why relying on open-source software packages like Log4J exposes enterprises to long-tail security patching risks.

Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor
Play section The security trade-offs of auto-updating software dependencies
The security trade-offs of auto-updating software dependencies thumbnail

The security trade-offs of auto-updating software dependencies

Distributing untethered updates through CDNs or automated package managers can rapidly propagate supply chain attacks to end users.

How to develop an autonomous car end-to-end: Robotic Drive and the mobility revolution
Play section Migrating to a software-centric component supply chain
Migrating to a software-centric component supply chain thumbnail

Migrating to a software-centric component supply chain

Vehicle manufacturers are securing control over system updates by converging separate component functionalities against generic underlying modules.

Simplifying edge app delivery: one workflow, thousands of devices
Play section Securing hardware enrollment via FDO specification and signing
Securing hardware enrollment via FDO specification and signing thumbnail

Securing hardware enrollment via FDO specification and signing

Adopting automated zero-touch provisioning and system image signing protects the broader software supply chain from rogue devices.

Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World
Play section Practical mitigation strategies for modern software supply chains
Practical mitigation strategies for modern software supply chains thumbnail

Practical mitigation strategies for modern software supply chains

Rebuilding immutable containers, migrating to memory-safe languages, and adopting zero-trust practices minimize the attack surface.

Your mix. Instantly.

More mixes