Bringing Provenance to Open Source - Lessons from Npm's Sigstore Integration
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore the challenges and solutions in bringing provenance to open source software in this 27-minute conference talk by Trevor Rosen and Zach Steindler from GitHub/npm. Delve into npm's integration with Sigstore to address the lack of verifiable links between packages and their source code. Learn about the complexities of securing build processes, the implications of developer identity verification, and the potential for applying these approaches to other package ecosystems. Gain insights into one of the most significant efforts in software supply chain security and consider fundamental perspectives on package provenance across the open source landscape.
Syllabus
Bringing Provenance to All of Open Source: Lessons from Npm’s... - Trevor Rosen & Zach Steindler
Taught by
Linux Foundation
Tags
Related Courses
Front-End Web UI Frameworks and ToolsThe Hong Kong University of Science and Technology via Coursera Using Open Source Web Tooling to Improve Development Proficiency
Microsoft via edX Front-End Web UI Frameworks and Tools: Bootstrap 4
The Hong Kong University of Science and Technology via Coursera Diseñando páginas web con Bootstrap 4
Universidad Austral via Coursera React 101 - basics complete & latest. Forms, routing, async
Udemy