Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Not Just Ticking a Box - Establishing Trust in Artifacts with Provenance

Linux Foundation via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore software artifact provenance and trust establishment in this 20-minute conference talk from the Linux Foundation's Open Source Summit. Learn why understanding where software artifacts come from and how they were produced is crucial for production environments, moving beyond mere compliance checkboxes to establish genuine trust. Discover the essential questions to ask about software provenance, including artifact origins, production processes, quality checks, and verification methods. Compare provenance details and capabilities across different systems including GitHub Actions, Tekton Chains, and Witness to understand the prerequisites for meaningful provenance verification. Gain practical insights into generating provenance attestations and implementing them for real-world value in production environments, with actionable strategies for using provenance data to make informed decisions about software artifact trustworthiness.

Syllabus

Not Just Ticking a Box – Establishing Trust in Artifacts with Proven... Andrew McNamara & Ralph Bean

Taught by

Linux Foundation

Reviews

Start your review of Not Just Ticking a Box - Establishing Trust in Artifacts with Provenance

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.