Главная
Study mode:
on
1
Intro
2
The Supply Chain
3
Unavailability
4
Defects
5
Bugs
6
Package Availability
7
Lack of Maintenance
8
Breaking Into Your Code
9
Python Nation
10
Colorama
11
NPM
12
Ecosystem
13
Electron
14
JavaScript
15
Mitigating Risks
16
The Dam Maintainer
17
Upgrades and Updates
18
Auditing
19
Summary
20
Everything
Description:
Explore the critical issue of supply chain security in modern software development through this 16-minute conference talk from linux.conf.au. Delve into the history of the software supply chain, examine recent security incidents involving third-party modules, and understand the risks associated with rapid development practices. Learn about the challenges faced by maintainers, the impact of unmaintained packages, and the potential vulnerabilities in popular ecosystems like npm and PyPI. Discover practical strategies to mitigate risks, including best practices for package management, regular audits, and responsible upgrade procedures. Gain valuable insights to enhance the security of your software projects and better navigate the complex landscape of third-party dependencies.

How Much Do You Trust That Package? Understanding the Software Supply Chain

linux.conf.au
Add to list
0:00 / 0:00