Power BI Fundamentals - Create visualizations and dashboards from scratch
Free courses from frontend to fullstack and AI
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk explains how software supply chain attacks happen and why open source ecosystems are vulnerable. It introduces security concepts and frameworks for protecting software integrity and evaluating the practices of dependencies.
Syllabus
Intro
OPEN SOURCE SUPPLY CHAIN SECURITY (AND WHY YOU SHOULD CARE)
OVERVIEW
AFFECTING OPEN SOURCE ECOSYSTEMS
UNAUTHORIZED CHANGES
COMPROMISED SOURCE REPO
BUILD FROM MODIFIED SOURCE
COMPROMISED BUILD PROCESS
USE COMPROMISED DEPENDENCY
UPLOAD MODIFIED PACKAGE
COMPROMISE PACKAGE REPO
USE COMPROMISED PACKAGE
WHAT QUESTIONS MIGHT WE WANT TO ANSWER?
TERMINOLOGY
SIGSTORE
SLSA EXPLAINED
SLSA 1.0
EVALUATING RISKS
TRANSITIVE DEPENDENCIES
WHAT'S THE LATEST AND GREATEST?
SUPPORT OPEN SOURCE
Taught by
PyCon US