YoVDO

Securing Your .NET Application Software Supply Chain

Offered By: NDC Conferences via YouTube

Tags

NDC Conferences Courses Software Supply Chain Security Courses Software Bill of Materials (SBOM) Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore hands-on techniques for securing a .NET application's software supply chain in this NDC Oslo 2021 conference talk. Delve into the complexities of modern software development processes and learn how to address security risks at various stages, from source code access to deployment. Examine real-world examples like SolarWinds and CodeCov to understand potential vulnerabilities. Discover practical strategies based on Google's SLSA framework and Software Bill of Materials (SBOM) concepts. Cover topics such as GIT commit signing, dependency confusion, third-party library security, reproducible builds, artifact signing, and pipeline security policies. Gain valuable insights into protecting your software development lifecycle and mitigating risks in the increasingly complex software supply chain landscape.

Syllabus

Intro
Securing your .NET application software supply chain
What is a Supply Chain?
GIT Commit Signing
Octopus Scanner - NetBeans
Visual Studio Code
Dependency Confusion
3rd Party Libraries
Security Scorecards - OpenSSF
Source Generators
Reproducible Build .NET
Signing artifacts
Automotive Industry
Car Supply Chain
SolarWinds Project Trebuchet
IBM OpenShift
Azure Pipelines Artifact Policy
Google SLSA


Taught by

NDC Conferences

Related Courses

GitHub Supply Chain Security Using GitGat
Linux Foundation via edX
Introduction to Security Principles in Cloud Computing
Google via Google Cloud Skills Boost
DevOps with GitHub and Azure: Implementing Software Supply Chain Security with GitHub
Pluralsight
Hardening Your Soft Software Supply Chain
Pluralsight
Secure Software Supply Chain: Using Cloud Build & Cloud Deploy to Deploy Containerized Applications
Google via Google Cloud Skills Boost