YoVDO

Where Is the GUAC? - Understanding Artifact Composition in Software Supply Chains

Offered By: Linux Foundation via YouTube

Tags

Software Supply Chain Security Courses GraphQL Courses Graph Databases Courses Vulnerability Management Courses Software Bill of Materials (SBOM) Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the Graph for Understanding Artifact Composition (GUAC) in this informative conference talk. Discover how GUAC integrates metadata about software projects, artifacts, and attestations to provide a comprehensive view of the software supply chain. Learn how organizations can leverage GUAC to quickly identify vulnerabilities, determine necessary package updates, and assess their software ecosystem's security. Understand the process of ingesting SBOMs and attestations from various sources into a GraphQL-abstracted graph database. Gain insights into how GUAC utilizes identity information and trust policies to identify counterfactuals and answer critical security queries. Explore the integration of OSV, deps.dev, and Scorecards to enrich the graph with essential information for a complete overview of the software supply chain. Discover how this extensive dataset, combined with GraphQL, enables automated policies to determine artifact authorization for production environments.

Syllabus

Where Is the GUAC? - Parth Patel, Kusari & Mihai Maruseac, Google


Taught by

Linux Foundation

Tags

Related Courses

Go Serverless with a Graph Database
A Cloud Guru
Advanced Data Engineering
Duke University via Coursera
Amazon Neptune Service Introduction
Amazon Web Services via AWS Skill Builder
Amazon Neptune Service Introduction (German)
Amazon Web Services via AWS Skill Builder
Amazon Neptune Service Introduction (German)
Amazon Web Services via AWS Skill Builder