Securing the Supply Chain with Witness - A Framework for Supply Chain Security
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Thank you to our Session Recording Sponsor
Witness Introduction
SLSA Level 4 - Providence Reqs
Witness' Trust Model
Signer Support
Cryptographic Document Support
Policy Verification
Use Case: Ensure all builds happened on approved infra
Use Case: Verify an artifact passed SAST testing
Use Case: IR - Upstream Build System Compromise
DEMO: SLSA 3 for a major project - SPIRE
Taught by
CNCF [Cloud Native Computing Foundation]