YoVDO

Securing the Supply Chain with Witness - A Framework for Supply Chain Security

Offered By: CNCF [Cloud Native Computing Foundation] via YouTube

Tags

Supply Chain Security Courses Cryptography Courses CI/CD Courses Cloud-Native Security Courses SLSA Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Learn about Witness, an open-source modular framework for supply chain security, in this 23-minute conference talk. Explore how Witness creates collections of attestations bound to the CI process, providing trusted sectors for policy enforcement. Discover the Witness trust model and its integration with cloud-native security tools like rekor, spire, cosign, and Kubernetes. Gain insights into SLSA Level 4 providence requirements, signer support, cryptographic document support, and policy verification. Examine use cases such as ensuring builds on approved infrastructure, verifying SAST testing, and handling upstream build system compromises. Watch a demonstration of implementing SLSA 3 for a major project using SPIRE.

Syllabus

Thank you to our Session Recording Sponsor
Witness Introduction
SLSA Level 4 - Providence Reqs
Witness' Trust Model
Signer Support
Cryptographic Document Support
Policy Verification
Use Case: Ensure all builds happened on approved infra
Use Case: Verify an artifact passed SAST testing
Use Case: IR - Upstream Build System Compromise
DEMO: SLSA 3 for a major project - SPIRE


Taught by

CNCF [Cloud Native Computing Foundation]

Related Courses

Building on Microsoft Sentinel Platform
Microsoft via YouTube
Securing Applications and Infrastructure on Kubernetes with Sysdig
Mirantis via YouTube
Container Escape in 2021
Hack In The Box Security Conference via YouTube
Running at Light Speed - Cloud Native Security Patterns
LASCON via YouTube
Controlled Mayhem With Cloud Native Security Pipelines
OWASP Foundation via YouTube