> Markdown version of [/playlists/software-supply-chain-security](https://www.wearedevelopers.com/playlists/software-supply-chain-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Playlist: Software supply chain security 16 videos · 18 moments · 55.6 minutes ## How your .NET software supply chain is open to attack : and how to fix it - **Understanding software supply chain threats and security risks** (00:03, 3min) — The software supply chain encompasses all build tools and dependencies, which are increasingly targeted by data exfiltration attacks. - **Essential best practices for securing nuget package configurations** (23:16, 5min) — Engineering teams prevent supply chain attacks by reserving package prefixes, signing binaries, clearing system defaults, and inspecting new targets. [Learn more](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) ## Building Trust Through Private and Verifiable AI - **Securing contextual storage and proving verifiable transparency** (11:37, 2min) — User-controlled encryption keys secure stored documents while hardware vendor attestation enables independent software assurance verification. [Learn more](https://www.wearedevelopers.com/videos/100013-building-trust-through-private-and-verifiable-ai) ## Reporting Active Exploits in 24 Hours: Are You Ready for the CRA? - **Mapping the complete software supply chain attack surface** (11:01, 2min) — Why comprehensive security requires validating build environments and commercial dependencies beyond open source component scanning. [Learn more](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Securing your application software supply-chain - **Integrating security across the application development lifecycle** (25:51, 2min) — Adopting a progressive approach to threat modeling supply chains ensures that security practices scale with complex modern workflows. - **Adopting the SLSA framework for supply chain maturity** (19:27, 3min) — Progressively implementing supply chain levels enables teams to automate verifiable provenance without manually juggling cryptographic keys. [Learn more](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) ## Security Pitfalls for Software Engineers - **Mitigating risks from supply chain attacks and vulnerable libraries** (10:26, 2min) — Exploited open source dependencies like Log4j highlight the absolute necessity for aggressive software supply chain oversight. [Learn more](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Making Teaching Code Less Academic and More Market-Ready - Peter Ruppel - **Implementing preventative cybersecurity to mitigate software supply chain risks** (16:07, 3min) — Teams must actively prioritize access control and foundational security checks instead of relying on delayed patching protocols. [Learn more](https://www.wearedevelopers.com/videos/1911-making-teaching-code-less-academic-and-more-market-ready-peter-ruppel) ## Building on Open Source: The New Product Playbook - **Gaining software supply chain visibility through upstream engagement** (14:10, 3min) — Participating directly in upstream development eliminates vendor bottlenecks and secures control over essential infrastructure dependencies. [Learn more](https://www.wearedevelopers.com/videos/100031-building-on-open-source-the-new-product-playbook) ## The AI Security Survival Guide: Practical Advice for Stressed-Out Developers - **Artificial intelligence components in the software supply chain** (00:00, 1min) — Integrating language models introduces inherited vulnerabilities into development workflows regardless of direct implementation. [Learn more](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Real-World Security for Busy Developers - **Evaluating supply chain risk through automated dependency reviews** (21:26, 2min) — Checking new package manifests against global advisory databases during branch merges prevents the introduction of critical software supply chain v... [Learn more](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## An alternative approach to digital sovereignty: Confidential Computing - **Securing digital supply chains using isolated build environments** (17:59, 1min) — Generating provenance proofs natively inside secure hardware guarantees the integrity of continuous software bills of materials. [Learn more](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) ## How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski - **Avoiding supply chain risks within standard software dependencies** (14:28, 1min) — Recognizing hidden threats located inside widely adopted package managers and binary compilation tools. [Learn more](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) ## Overcome your trust issues! In a world of fake data, Data Provenance FTW - **Vulnerabilities within the cyber software supply chain** (00:03, 3min) — Why relying on open-source software packages like Log4J exposes enterprises to long-tail security patching risks. [Learn more](https://www.wearedevelopers.com/videos/784-overcome-your-trust-issues-in-a-world-of-fake-data-data-provenance-ftw) ## Coffee with Developers with Feross Aboukhadijeh of Socket about the xz backdoor - **The security trade-offs of auto-updating software dependencies** (27:19, 5min) — Distributing untethered updates through CDNs or automated package managers can rapidly propagate supply chain attacks to end users. [Learn more](https://www.wearedevelopers.com/videos/879-coffee-with-developers-with-feross-aboukhadijeh-of-socket-about-the-xz-backdoor) ## How to develop an autonomous car end-to-end: Robotic Drive and the mobility revolution - **Migrating to a software-centric component supply chain** (49:45, 4min) — Vehicle manufacturers are securing control over system updates by converging separate component functionalities against generic underlying modules. [Learn more](https://www.wearedevelopers.com/videos/22-how-to-develop-an-autonomous-car-end-to-end-robotic-drive-and-the-mobility-revolution) ## Simplifying edge app delivery: one workflow, thousands of devices - **Securing hardware enrollment via FDO specification and signing** (06:07, 2min) — Adopting automated zero-touch provisioning and system image signing protects the broader software supply chain from rogue devices. [Learn more](https://www.wearedevelopers.com/videos/1608-simplifying-edge-app-delivery-one-workflow-thousands-of-devices) ## Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World - **Practical mitigation strategies for modern software supply chains** (17:04, 3min) — Rebuilding immutable containers, migrating to memory-safe languages, and adopting zero-trust practices minimize the attack surface. [Learn more](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world)