Workshop
Sponsored
Virtual
LiveDay NYC
LiveDay LDN
On demand
BST
7:00 am
EDT
Jun 24

Securing the software supply chain: Open source for the SDLC

Discover how Dev(Sec)Ops enables organizations secure the software supply chain by adopting OpenSSF/Linux Foundation and CNCF graduated projects tools to integrate into the workflows to improve the Software Development Life Cycle (SDLC).
With the complexity of Software Development, securing the software supply chain has never been more critical and it becomes crucial with the Cyber Resilience Act (CRA).

Join Kairo De Araujo as he guides you through essential CNCF and OpenSSF projects designed to address software supply chain security challenges. You'll discover in-toto (https://in-toto.io/), a framework that provides provenance attestation allowing traceability and verification of your software's journey from development to deployment, augmented by tools like Witness and Archivista for enhanced artifact provenance and monitoring. You'll also explore The Update Framework (TUF) (https://theupdateframework.io/) and Repository for TUF (RSTUF) (https://rstuf.org/), powerful frameworks for secure software distribution that ensure the integrity and authenticity of distributed software, attestations and SBOMs. These proven solutions have been successfully implemented by private organizations including Datadog, Lockheed Martin, and GitHub, as well as major open source projects like PyPI, NPM, and RubyGems. As a maintainer of these projects, Kairo will demonstrate how you can implement these tools to safeguard your software supply chain, reduce risks, and enhance SDLC trust. Expect actionable insights, hands-on examples, and a clear roadmap for integrating these solutions into your existing workflows.
Workshop
Sponsored
Tue 24 June
Virtual
Virtual
Virtual
On demand

Securing the software supply chain: Open source for the SDLC

Discover how Dev(Sec)Ops enables organizations secure the software supply chain by adopting OpenSSF/Linux Foundation and CNCF graduated projects tools to integrate into the workflows to improve the Software Development Life Cycle (SDLC).
Tue 24 June
EDT time
EDT
1:00 pm
CEST
7:00 am
EDT
BST
Presented by
Panelist
Panelist
Panelist
Moderator
Kairo De Araujo
Software Engineer - Open Source Security, Eclipse Foundation
Tell everyone
With the complexity of Software Development, securing the software supply chain has never been more critical and it becomes crucial with the Cyber Resilience Act (CRA).

Join Kairo De Araujo as he guides you through essential CNCF and OpenSSF projects designed to address software supply chain security challenges. You'll discover in-toto (https://in-toto.io/), a framework that provides provenance attestation allowing traceability and verification of your software's journey from development to deployment, augmented by tools like Witness and Archivista for enhanced artifact provenance and monitoring. You'll also explore The Update Framework (TUF) (https://theupdateframework.io/) and Repository for TUF (RSTUF) (https://rstuf.org/), powerful frameworks for secure software distribution that ensure the integrity and authenticity of distributed software, attestations and SBOMs. These proven solutions have been successfully implemented by private organizations including Datadog, Lockheed Martin, and GitHub, as well as major open source projects like PyPI, NPM, and RubyGems. As a maintainer of these projects, Kairo will demonstrate how you can implement these tools to safeguard your software supply chain, reduce risks, and enhance SDLC trust. Expect actionable insights, hands-on examples, and a clear roadmap for integrating these solutions into your existing workflows.
Workshop
Sponsored
Virtual
LiveDay NYC
LiveDay LDN
On demand
Tue 24 June

Securing the software supply chain: Open source for the SDLC

Discover how Dev(Sec)Ops enables organizations secure the software supply chain by adopting OpenSSF/Linux Foundation and CNCF graduated projects tools to integrate into the workflows to improve the Software Development Life Cycle (SDLC).
1:00 pm
CEST
BST
7:00 am
EDT
Duration:
90min
60min
Presented by
Tell everyone
With the complexity of Software Development, securing the software supply chain has never been more critical and it becomes crucial with the Cyber Resilience Act (CRA).

Join Kairo De Araujo as he guides you through essential CNCF and OpenSSF projects designed to address software supply chain security challenges. You'll discover in-toto (https://in-toto.io/), a framework that provides provenance attestation allowing traceability and verification of your software's journey from development to deployment, augmented by tools like Witness and Archivista for enhanced artifact provenance and monitoring. You'll also explore The Update Framework (TUF) (https://theupdateframework.io/) and Repository for TUF (RSTUF) (https://rstuf.org/), powerful frameworks for secure software distribution that ensure the integrity and authenticity of distributed software, attestations and SBOMs. These proven solutions have been successfully implemented by private organizations including Datadog, Lockheed Martin, and GitHub, as well as major open source projects like PyPI, NPM, and RubyGems. As a maintainer of these projects, Kairo will demonstrate how you can implement these tools to safeguard your software supply chain, reduce risks, and enhance SDLC trust. Expect actionable insights, hands-on examples, and a clear roadmap for integrating these solutions into your existing workflows.
Workshop
Sponsored
Virtual
LiveDay NYC
LiveDay LDN
On demand
BST
7:00 am
EDT
Jun 24

Securing the software supply chain: Open source for the SDLC

Discover how Dev(Sec)Ops enables organizations secure the software supply chain by adopting OpenSSF/Linux Foundation and CNCF graduated projects tools to integrate into the workflows to improve the Software Development Life Cycle (SDLC).
Presented by
Panelist
Panelist
Panelist
Host
Kairo De Araujo
Software Engineer - Open Source Security, Eclipse Foundation
Tell everyone
Sign up now