> Markdown version of [/videos/1038-open-source-secure-software-supply-chain-in-action?t=450](https://www.wearedevelopers.com/videos/1038-open-source-secure-software-supply-chain-in-action?t=450). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Open Source Secure Software Supply Chain in action Software supply chain attacks are escalating. Protect your development lifecycle using open-source tools like Sigstore and Tekton. Watch a live demonstration of shifting your pipeline security left. - **Speakers:** [Natale Vinto](https://www.wearedevelopers.com/@natale-vinto) - **Event:** World Congress 2024 - **Published:** August 20, 2024 - **Duration:** 32:55 - **URL:** https://www.wearedevelopers.com/videos/1038-open-source-secure-software-supply-chain-in-action ## Summary The escalating frequency of software supply chain attacks has made securing the development lifecycle a critical priority for engineering teams. Moving beyond traditional DevSecOps, modern supply chain security requires organizations to safeguard code, fortify build systems, and continuously monitor applications at runtime. To mitigate these risks, developers can leverage a robust ecosystem of open-source tools to build an opinionated, secure pipeline.<br><br>Key technologies include Sigstore for keyless commit and artifact signing, Tekton and Tekton Chains for pipeline provenance, and Quay with Clair for continuous registry scanning. By adhering to frameworks like SLSA (Supply chain Levels for Software Artifacts), teams can cryptographically verify attestation and provenance, ensuring that neither the build environment nor the artifacts have been compromised. Generating a comprehensive SBOM (Software Bill of Materials) provides an inventory of all dependencies, which is critical for rapid vulnerability remediation.<br><br>A live demonstration highlights the practical application of shifting security left. By integrating dependency analytics directly into the IDE, developers can proactively remediate transitive vulnerabilities and update base images before committing code. Furthermore, utilizing internal developer portals like Backstage to scaffold projects ensures new services automatically inherit secure workflows and runtime policy enforcement via Kubernetes-native tools like StackRox. Adopting these automated, secure-by-default workflows minimizes developer friction while maintaining strict compliance with industry standards. **Keywords:** software supply chain security, devsecops methodologies, software composition analysis, SBOM generation, SLSA compliance, artifact attestation, cryptographic provenance, keyless code signing, sigstore integration, tekton pipelines, container image scanning, transitive vulnerability remediation, runtime policy enforcement, internal developer portals ## Chapters 1. **Understanding the rise of supply chain attacks** (00:02) — An overview of why supply chain attacks are increasing and the importance of mitigating vulnerabilities. 1. **Core domains of software supply chain security** (02:50) — The critical role of software composition, content signing, and policy enforcement in securing applications. 1. **Open source tools for securing development pipelines** (04:30) — Implementing open source solutions to identify malicious code and safeguard build systems early. 1. **Securing deployments and enabling continuous monitoring** (07:30) — Strategies for checking compliance during deployment and monitoring runtime execution using open source tools. 1. **Essential supply chain security terminology and standards** (09:08) — A review of critical acronyms and the SALSA framework levels for defining platform security. 1. **Designing a security-augmented software delivery process** (11:31) — Implementing a shift-left approach with opinionated pipelines and keyless signing workflows. 1. **Scaffolding secure applications with developer portal templates** (18:50) — Using enterprise portal templates to automatically configure base images, secure pipelines, and deployments. 1. **Scanning dependencies and mitigating vulnerabilities locally** (21:59) — Utilizing IDE extensions to analyze dependencies and update base images before committing code. 1. **Keyless commit signing and secure pipeline execution** (26:04) — Authenticating via OIDC to sign commits seamlessly and trigger automated security checks. 1. **Analyzing software bills of materials and runtime compliance** (28:02) — Inspecting generated SBOMs and verifying runtime container compliance against industry security benchmarks. ## Related Moments - [Mapping the complete software supply chain attack surface](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) (from "Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?") - [Understanding software supply chain threats and security risks](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) (from "How your .NET software supply chain is open to attack : and how to fix it") - [Introduction to supply chain security principles](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) (from "Oops! Stories of supply chain shenanigans") - [Core principles for implementing DevSecOps in teams](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") - [Integrating security across the application development lifecycle](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) (from "Securing your application software supply-chain") - [Exploring the mechanics of software supply chain attacks](https://www.wearedevelopers.com/videos/1841-wearedevelopers-live-bitpanda-s-ai-first-approach) (from "WeAreDevelopers LIVE - Bitpanda’s AI First Approach") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) ## Related Jobs - [Senior Supply Chain Security Engineer](https://www.wearedevelopers.com/jobs/48462-senior-supply-chain-security-engineer) at **Docker, Inc.** - [Senior Principal Software Engineer, Docker and Ecosystem](https://www.wearedevelopers.com/jobs/48456-senior-principal-software-engineer-docker-and-ecosystem) at **Docker, Inc.** - [Senior Software Engineer, Secure Build](https://www.wearedevelopers.com/jobs/48461-senior-software-engineer-secure-build) at **Docker, Inc.** - [Principal Software Engineer, Docker Hardened Images](https://www.wearedevelopers.com/jobs/48453-principal-software-engineer-docker-hardened-images) at **Docker, Inc.** - [Manager, Engineering, Secure Build and SCS Services](https://www.wearedevelopers.com/jobs/48447-manager-engineering-secure-build-and-scs-services) at **Docker, Inc.** - [Senior Security Engineer, Docker Desktop](https://www.wearedevelopers.com/jobs/48457-senior-security-engineer-docker-desktop) at **Docker, Inc.**