Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Builds You (and Others) Can Trust - Meet the AMPEL Policy Engine

Linux Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn about AMPEL, an open source policy engine designed to address supply chain security challenges in software development. Discover how this multi-purpose tool serves as the missing piece in the supply chain ecosystem by natively understanding in-toto attestations, verifying keyless Sigstore signatures, and comprehending any attestation predicate type. Explore AMPEL's embeddable capabilities that enable it to examine SBOMs and warn about problematic dependencies, interpret security scans to gate builds when vulnerabilities are detected, and prevent artifact publishing when security frameworks aren't met. Understand how AMPEL is building an ecosystem of tools, starting with the bnd attester, that can work across the Software Development Life Cycle (SLDC) to secure CI/CD systems. Examine practical examples demonstrating how AMPEL ensures compliance in hardened pipelines through verifiable evidence, making the wealth of security metadata generated by the supply chain security community finally actionable and useful for developers and organizations seeking to build trustworthy software.

Syllabus

Builds You (and Others) Can Trust: Meet the AMPEL Policy Engine - Adolfo García Veytia

Taught by

Linux Foundation

Reviews

Start your review of Builds You (and Others) Can Trust - Meet the AMPEL Policy Engine

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.