Spice Check - Building an End-to-End SLSA Implementation
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore how to implement end-to-end SLSA (Supply-chain Levels for Software Artifacts) protection in this 23-minute conference talk from KubeCon + CloudNativeCon. Discover the latest developments in software supply chain security, including the newly released SLSA 1.2 specification and its innovative Source track feature. Learn how to leverage the AMPEL policy engine to enforce security policies throughout the entire software development lifecycle, from source code to release. Examine practical approaches to hardening software repositories and builds using signed, verifiable evidence and unforgeable attestations. Understand how to instrument comprehensive protection for software projects with minimal code implementation by utilizing community-curated policies. Gain insights into protecting software factories through policy enforcement at each stage of development, ensuring robust supply chain security through attested data from various tools.
Syllabus
Spice Check: Building an E2E SLSA Implementation - Adolfo GarcÃa Veytia, Carabiner Systems
Taught by
CNCF [Cloud Native Computing Foundation]