Where Is the GUAC? - Understanding Artifact Composition in Software Supply Chains
Offered By: Linux Foundation via YouTube
Course Description
Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the Graph for Understanding Artifact Composition (GUAC) in this informative conference talk. Discover how GUAC integrates metadata about software projects, artifacts, and attestations to provide a comprehensive view of the software supply chain. Learn how organizations can leverage GUAC to quickly identify vulnerabilities, determine necessary package updates, and assess their software ecosystem's security. Understand the process of ingesting SBOMs and attestations from various sources into a GraphQL-abstracted graph database. Gain insights into how GUAC utilizes identity information and trust policies to identify counterfactuals and answer critical security queries. Explore the integration of OSV, deps.dev, and Scorecards to enrich the graph with essential information for a complete overview of the software supply chain. Discover how this extensive dataset, combined with GraphQL, enables automated policies to determine artifact authorization for production environments.
Syllabus
Where Is the GUAC? - Parth Patel, Kusari & Mihai Maruseac, Google
Taught by
Linux Foundation
Tags
Related Courses
Go Serverless with a Graph DatabaseA Cloud Guru Advanced Data Engineering
Duke University via Coursera Amazon Neptune Service Introduction
Amazon Web Services via AWS Skill Builder Amazon Neptune Service Introduction (German)
Amazon Web Services via AWS Skill Builder Amazon Neptune Service Introduction (German)
Amazon Web Services via AWS Skill Builder