Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

Dirty Dancing - Untrustworthy SLSA Build Provenance

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore the critical gaps between SLSA Build Level 3 certification and actual software supply chain security in this 23-minute conference talk that challenges common assumptions about build provenance trustworthiness. Examine the official slsa-github-generator workflow as a case study to understand how provenance is generated and what verification processes actually validate versus what they appear to guarantee. Learn to identify scenarios where provenance attestations may seem valid but should not be trusted, including subtle vulnerabilities in build tooling, configuration errors, and verification gaps that can compromise software supply chain integrity. Discover practical strategies for comparing alternative builders against official SLSA tooling, recognizing red flags in provenance attestations, and implementing SLSA tools correctly to establish genuine trust rather than superficial compliance. Gain essential knowledge for both software consumers and maintainers to critically evaluate build provenance claims and make informed decisions about software supply chain security in cloud native environments.

Syllabus

Dirty Dancing - Untrustworthy SLSA Build Provenance - John Kjell, ControlPlane

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of Dirty Dancing - Untrustworthy SLSA Build Provenance

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.