Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Securing Build Platforms: Enhancing Trust in Software Distribution

Linux Plumbers Conference via YouTube

Overview

Explore the critical importance of securing build platforms in software development during this 35-minute conference talk from the Linux Plumbers Conference. Delve into the growing concerns surrounding the software chain of trust and its impact on security, compliance, and reliability. Examine how Linux distributions mitigate trust decisions for consumers and the challenges in evaluating distribution trustworthiness. Learn about npm's adoption of SLSA and Sigstore for build provenance, and consider the complexities of applying similar techniques to distribution build platforms. Investigate the efforts of SUSE and Flatcar Linux in this area, along with their unresolved verification issues. Gain insights into potential solutions for Linux distribution build platforms, with a focus on OpenEmbedded/Yocto Project and proof-of-concept experiments in the yocto-autobuilder2 system.

Syllabus

Securing build platforms - Joshua Lock

Taught by

Linux Plumbers Conference

Reviews

Start your review of Securing Build Platforms: Enhancing Trust in Software Distribution

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.