World Congress 2024 • Aug 20, 2024 • Session details

Open Source Secure Software Supply Chain in action

Natale Vinto

Software supply chain attacks are escalating. Protect your development lifecycle using open-source tools like Sigstore and Tekton. Watch a live demonstration of shifting your pipeline security left.

Pause
Mute Enter Fullscreen
#1 about 3 min

Understanding the rise of supply chain attacks

An overview of why supply chain attacks are increasing and the importance of mitigating vulnerabilities.

#2 about 2 min

Core domains of software supply chain security

The critical role of software composition, content signing, and policy enforcement in securing applications.

#3 about 3 min

Open source tools for securing development pipelines

Implementing open source solutions to identify malicious code and safeguard build systems early.

#4 about 2 min

Securing deployments and enabling continuous monitoring

Strategies for checking compliance during deployment and monitoring runtime execution using open source tools.

#5 about 3 min

Essential supply chain security terminology and standards

A review of critical acronyms and the SALSA framework levels for defining platform security.

#6 about 8 min

Designing a security-augmented software delivery process

Implementing a shift-left approach with opinionated pipelines and keyless signing workflows.

#7 about 4 min

Scaffolding secure applications with developer portal templates

Using enterprise portal templates to automatically configure base images, secure pipelines, and deployments.

#8 about 5 min

Scanning dependencies and mitigating vulnerabilities locally

Utilizing IDE extensions to analyze dependencies and update base images before committing code.

#9 about 2 min

Keyless commit signing and secure pipeline execution

Authenticating via OIDC to sign commits seamlessly and trigger automated security checks.

#10 about 5 min

Analyzing software bills of materials and runtime compliance

Inspecting generated SBOMs and verifying runtime container compliance against industry security benchmarks.

Matching moments

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:36 min

Understanding software supply chain threats and security risks

Andrei Epure Andrei Epure · World Congress 2024

1:37 min

Introduction to supply chain security principles

Zbyszek Tenerowicz · LIVE

4:00 min

Core principles for implementing DevSecOps in teams

Aarno Aukia · LIVE

2:35 min

Integrating security across the application development lifecycle

Niels Tanis Niels Tanis · World Congress 2022

3:39 min

Exploring the mechanics of software supply chain attacks

Chris Heilmann Chris Heilmann +2 · LIVE