Building SLSA 3 Conformant Attestors for Artifacts Generated on GitHub
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore the implementation of SLSA 3 Conformant Attestors for artifacts generated on GitHub in this informative conference talk by Ian Lewis and Asra Ali from Google. Dive into the Supply chain Levels for Software Artifacts (SLSA) security framework and its growing adoption in industry and open source projects. Learn about generating SLSA provenance attestations for various artifacts, including vulnerability scanner results and SBOMs. Discover a recent extension of the SLSA framework that simplifies the process of creating compliant attestors by wrapping existing tools. Examine real-world examples of SLSA builders for package managers like npm and maven. Gain insights into the challenges faced and lessons learned during implementation. By the end of this talk, acquire the necessary background to create SLSA provenance attestations for your own tools and outputs.
Syllabus
Building SLSA 3 Conforment Attestors for Artifacts Generated on GitHub- Ian Lewis & Asra Ali, Google
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Introduction to Agile Software Development: Tools & TechniquesUniversity of California, Berkeley via edX Advanced Topics and Techniques in Agile Software Development
University of California, Berkeley via edX The Data Scientist’s Toolbox
Johns Hopkins University via Coursera How to Use Git and GitHub
Udacity Desarrollo de Videojuegos 3D en Unity: Una Introducción
Universidad de los Andes via Coursera