Automated End-to-End VEX Streams You Can Trust
Offered By: OpenSSF via YouTube
Course Description
Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the groundbreaking advancements in Vulnerability Exploitability Exchange (VEX) technology in this 19-minute conference talk by Adolfo García Veytia from Stacklok. Dive into the evolution of VEX over the past two years and discover how the recent adoption of OpenVEX in Go security tooling has revolutionized the field. Learn about the creation of automated VEX streams that eliminate human intervention and provide trustworthy vulnerability assessments based on compiler-generated reachability data. Witness the construction of a trusted end-to-end VEX stream, from code to scanner, and gain insights into the intricate details of a VEX document. Uncover the latest developments in the OpenVEX ecosystem and understand how this milestone marks a new era of maturity in vulnerability communication and management.
Syllabus
Finally! Automated End-to-End VEX Streams You Can Trust - Adolfo García Veytia, Stacklok
Taught by
OpenSSF
Related Courses
GitHub Supply Chain Security Using GitGatLinux Foundation via edX Introduction to Security Principles in Cloud Computing
Google via Google Cloud Skills Boost DevOps with GitHub and Azure: Implementing Software Supply Chain Security with GitHub
Pluralsight Hardening Your Soft Software Supply Chain
Pluralsight Secure Software Supply Chain: Using Cloud Build & Cloud Deploy to Deploy Containerized Applications
Google via Google Cloud Skills Boost