YoVDO

Automated End-to-End VEX Streams You Can Trust

Offered By: OpenSSF via YouTube

Tags

VEX Courses Software Supply Chain Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the groundbreaking advancements in Vulnerability Exploitability Exchange (VEX) technology in this 19-minute conference talk by Adolfo García Veytia from Stacklok. Dive into the evolution of VEX over the past two years and discover how the recent adoption of OpenVEX in Go security tooling has revolutionized the field. Learn about the creation of automated VEX streams that eliminate human intervention and provide trustworthy vulnerability assessments based on compiler-generated reachability data. Witness the construction of a trusted end-to-end VEX stream, from code to scanner, and gain insights into the intricate details of a VEX document. Uncover the latest developments in the OpenVEX ecosystem and understand how this milestone marks a new era of maturity in vulnerability communication and management.

Syllabus

Finally! Automated End-to-End VEX Streams You Can Trust - Adolfo García Veytia, Stacklok


Taught by

OpenSSF

Related Courses

GitHub Supply Chain Security Using GitGat
Linux Foundation via edX
Introduction to Security Principles in Cloud Computing
Google via Google Cloud Skills Boost
DevOps with GitHub and Azure: Implementing Software Supply Chain Security with GitHub
Pluralsight
Hardening Your Soft Software Supply Chain
Pluralsight
Secure Software Supply Chain: Using Cloud Build & Cloud Deploy to Deploy Containerized Applications
Google via Google Cloud Skills Boost