Hardening the Kubernetes Software Supply Chain Through Better Transparency
CNCF [Cloud Native Computing Foundation] via YouTube
2,000+ Free Courses with Certificates: Coding, AI, SQL, and More
AI, Data Science & Cloud Certificates from Google, IBM & Meta
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains efforts to make the Kubernetes software supply chain more transparent and secure through SPDX bills of materials, automated release artifact verification, and digital signing. It also demonstrates tools created by SIG Release for use in other projects.
Syllabus
Introduction
Past Years: Foundations a New Release Process
Ownership of the Container Image Promoter
Current Efforts for 2021 and Beyond
SLSA Compliance
People+Code (We need to talk)
Closing Remarks
Taught by
CNCF [Cloud Native Computing Foundation]