Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Building the Software Supply Chain on Docker Official Images

Docker via YouTube

Overview

Explore Docker's approach to securing the software supply chain in this 33-minute DockerCon 2023 talk. Discover how Docker is modernizing its toolchain to provide security by default, including software bill of materials (SBOMs), provenance, cryptographic signing, and verification. Learn about the application of these principles to Docker Official Images (DOI), a significant component in most teams' software supply chains. Gain insights into how Docker and BastionZero leverage open standards like The Update Framework (TUF) and Supply-Chain Levels for Software Artifacts (SLSA), along with a novel decentralized signing approach using modern cryptographic methods. Understand how these innovations are being incorporated into open-source projects like BuildKit and the Docker CLI to enhance software supply chain metadata and verification.

Syllabus

Building the Software Supply Chain on Docker Official Images (DockerCon 2023)

Taught by

Docker

Reviews

Start your review of Building the Software Supply Chain on Docker Official Images

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.