Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to implement end-to-end SLSA (Supply-chain Levels for Software Artifacts) protection for software projects in this conference talk. Explore the newly released SLSA 1.2 specification and its source track capabilities, which enable comprehensive security policies from source code to release. Discover how to use the AMPEL policy engine to enforce protections at each stage of the software development lifecycle using signed, verifiable evidence. Walk through practical implementation of community-curated policies that provide complete software factory protection with minimal code requirements. Understand how to leverage unforgeable evidence and attestation data from various tools to harden software repositories and builds, creating a robust security framework for modern software supply chains.
Syllabus
Spice Check: Building an E2E SLSA Implementation - Adolfo GarcÃa Veytia, Carabiner Systems
Taught by
OpenSSF