Overview
Explore a real-world case study on securing a large-scale open-source packaging pipeline in this 43-minute conference talk. Gain insights into the architecture of an open-source package build pipeline, from acquisition to installation, and learn about common gaps and attacks. Discover the concrete steps taken to overcome real challenges encountered and the positive outcomes achieved. Understand how respected open-source security designs like The Update Framework, Sigstore, and in-toto were utilized, and how the Supply chain Levels for Software Artifacts (SLSA) framework was employed to organize and drive security improvement efforts. Conclude with valuable guidance for implementing similar security measures in your own organization's software supply chain.
Syllabus
Software Supply Chain Security Case Study at Anaconda - Sebastien Awwad, Anaconda
Taught by
Linux Foundation