Improve Vulnerability Management with OCI Artifacts - It Is That Easy
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Discover how to enhance vulnerability management practices using OCI artifacts in this 36-minute conference talk from CNCF. Learn about the recent advancements in supply chain security, including the popularization of standard Software Bill of Materials (SBOMs) and signed attestations. Explore the challenges of efficiently utilizing SBOMs at scale and how the OCI artifacts specification elegantly solves these issues. Gain insights into signing images, storing and signing SBOMs, scan results, and other important supply chain-related attestations alongside relevant artifacts in the registry. Understand how to leverage open-source tools like Trivy, Notary, and ORAS to improve vulnerability management practices. Discover how these techniques can be applied to various OCI artifacts, including WASM, packages, and libraries.
Syllabus
Improve Vulnerability Management with OCI Artifacts -It Is That Easy! - Itay Shakury & T Mladenov
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Securing the Container Supply Chain with Notary, TUF, and GatekeeperLinux Foundation via YouTube Using Docker Content Trust with Kubernetes Admission Controllers to Secure Runtime
Docker via YouTube Security Update: LinuxKit, Security Scanning, and Notary - Moby Summit
Docker via YouTube Securing the Software Supply Chain with TUF and Docker - Protecting Against Distribution Attacks
Docker via YouTube TUF-En Up Your Signatures - Enhancing Software Distribution Security
CNCF [Cloud Native Computing Foundation] via YouTube