The Chain of Trust - Towards SLSA L3 with Tekton Trusted Artifacts
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore the critical aspects of securing software supply chains in this 40-minute conference talk from the Cloud Native Computing Foundation (CNCF). Dive into Tekton's implementation of trusted resources, provenance, and Sigstore integration to combat the rising threat of supply chain attacks. Learn about the Data Interface SIG's efforts to provide first-class support for artifacts while adhering to key standards like SLSA, in-toto, and CDEvents. Discover the design of new artifact-related features and gain insights into the project roadmap. Understand how to secure artifacts in Tekton and contribute to discussions on enhancing software supply chain security. Join Jerop Kipruto from Google and Andrea Frittoli from IBM as they share successes, lessons learned, and strategies for preserving the chain of trust in build systems.
Syllabus
The Chain of Trust: Towards SLSA L3 with Tekton Trusted Artifacts - Jerop Kipruto & Andrea Frittoli
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
From Monolith to MicroservicesDocker via YouTube AWS: CI/CD Pipelines and Deployment Strategies
Whizlabs via Coursera Securing the Build and Deployment Pipeline - Challenges and Best Practices
OWASP Foundation via YouTube High-Security, Zero-Connectivity and Air-Gapped Clouds - Delivering Complex Software with OCM and Flux
CNCF [Cloud Native Computing Foundation] via YouTube Managing Artifacts at Scale for CI and Data Processing
CNCF [Cloud Native Computing Foundation] via YouTube