Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Learn Backend Development Part-Time, Online
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This session demonstrates ways to reduce security risks across a .NET application's software supply chain, using guidance from Google SLSA and concepts such as software bills of materials. It covers source code, third-party libraries, development tools, build servers, and release artifacts.
Syllabus
Intro
Securing your .NET application software supply chain
What is a Supply Chain?
GIT Commit Signing
Octopus Scanner - NetBeans
Visual Studio Code
Dependency Confusion
3rd Party Libraries
Security Scorecards - OpenSSF
Source Generators
Reproducible Build .NET
Signing artifacts
Automotive Industry
Car Supply Chain
SolarWinds Project Trebuchet
IBM OpenShift
Azure Pipelines Artifact Policy
Google SLSA
Taught by
NDC Conferences