YoVDO

Securing Open Source Software Supply Chain - Continuous Secure Software Ingestion

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Supply Chain Security Courses Software Composition Analysis Courses Tekton Courses Open Policy Agent Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the challenges and solutions for securing open-source software (OSS) ingestion in enterprise environments through this 26-minute conference talk by James Holland from Citi. Learn about the limitations of package managers in security checking and the need for additional measures to ensure safe OSS usage. Discover the Continuous Secure Software Ingestion (CSSI) application, a policy-driven system built on Tekton and Open Policy Agent (OPA), designed to perform continuous secure ingestion from various sources, including Google AOS. Gain insights into the additional constraints placed on downstream enterprise Software Composition Analysis (SCA) tooling to handle the resulting data graph. Understand the importance of automated grooming of OSS artifacts and the implementation of robust security checks during the ingestion process and beyond.

Syllabus

How’s Your Supply Chain with Your Insecure OSS Ingestion? - James Holland, Citi


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

DevSecOps Fundamentals
Cybrary
DevSecOps: Adding Security Testing Tools to Pipelines
Pluralsight
Inspecting Open Source Software Packages for Security and License Compliance
Pluralsight
Security Instrumentation - The Future of Software Security
LASCON via YouTube
5 Open Source Security Tools All Developers Should Know About
All Things Open via YouTube