YoVDO

Ergonomic Codesigning for the Python Ecosystem with Sigstore

Offered By: PyCon US via YouTube

Tags

PyCon US Courses Supply Chain Security Courses Key Management Courses Sigstore Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the future of code signing in the Python packaging ecosystem through this PyCon US talk by William Woodruff. Dive into the world of Sigstore, a revolutionary approach that allows package maintainers and users to sign and verify the authenticity of Python packages without the complexities of PGP. Gain insights into the cryptographic fundamentals of code signing and understand how Sigstore eliminates the need for long-term key material. Learn about the ongoing efforts to integrate Sigstore into Python packaging, including the standardization process and foundational work required for introducing a new code signing format. Discover the security model of Sigstore and the guarantees it provides for the Python packaging ecosystem. Get a comprehensive overview of the current state of Sigstore for Python, future goals, and ways to contribute to this important initiative in supply chain security.

Syllabus

Python is everywhere
let's talk about "supply chain security"
codesigning: a quick overview
codesigning for packaging ecosystems
codesigning for Python packaging: status quo
solving identity and key management with Sigstore
sunlight is the best disinfectant
Sigstore for Python: where we are
Sigstore for Python: where we want to be
Sigstore for Python: how you can help


Taught by

PyCon US

Related Courses

Securing Your Software Supply Chain with Sigstore
Linux Foundation via edX
Hands-on Introduction to Sigstore - Securing the Software Supply Chain
Rawkode Academy via YouTube
Protecting the World's Greatest Open Source Ecosystem with Sigstore
Devoxx via YouTube
PGP vs Sigstore - The Match at Maven Central
Devoxx via YouTube
Securing Your Infrastructure as Code Pipeline
Linux Foundation via YouTube