GUAC Verification for Software Supply Chain Security
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore the critical role of up-to-date information in software supply chain security through this conference talk. Delve into the implementation of Executive Order 14028, examining the vast metadata from SBOMs, SLSA attestations, vulnerability information, and in-toto ITE-6 attestations. Learn about projects like GUAC and Trustification for effective data collection and analysis. Discover how to integrate OPA with GUAC to create policies that determine whether artifacts are allowed to run in specific environments based on security assessments. Gain insights into enhancing decision-making processes for software deployment and security compliance in cloud native computing.
Syllabus
You Shall Not Pass! Unless You Are GUAC Verified - Parth Patel, Kusari & Dejan Bosanac, Red Hat
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Ketchup, Mustard, and Relish of Software Supply Chain Security - Panel DiscussionLinux Foundation via YouTube SLSA in Action: Securing the Software Supply Chain
Linux Foundation via YouTube Securing Your Supply Chain by Building with FRSCA
Linux Foundation via YouTube Open Tools for Secure Supply Chains in Kubernetes - From Release Engineering
Linux Foundation via YouTube Google SLSA and NIST SSDF - Emerging Software Supply Chain Security Best Practices
Linux Foundation via YouTube