Главная
Study mode:
on
1
Introduction
2
The problem
3
Community package repositories
4
The problem with signatures
5
How to make signing viable
6
The update framework
7
What is a tough implementation
8
What is a role
9
Example repository
10
PEP458
11
PEP480
12
PEP480 in use
13
Suggestions
14
Simple vs Complex
15
What could the PEPs do better
16
The wider ecosystem
17
QuestionsComments
Description:
Explore the challenges and solutions in improving package repository security in this 42-minute conference talk by Jussi Kukkonen from Google. Delve into the evolution of community package repositories like PyPI and NPM, examining the obstacles hindering the adoption of modern security practices. Learn about practical examples, including PyPI's efforts to integrate The Update Framework (TUF). Discover the proposed Repository Playground collaboration project, aimed at defining best practices and workflows beyond white papers. Gain insights into topics such as community package repositories, signature problems, TUF implementation, PEP458, PEP480, and suggestions for improving security in the wider ecosystem.

Improving Package Repository Security - From White Papers to Practice

Linux Foundation
Add to list
0:00 / 0:00