Главная
Study mode:
on
1
Introduction
2
What is the Secure Software Factory
3
What does the Secure Software Factory do
4
Build Environment
5
Example Build
6
What is SFF
7
SFF Defaults
8
SFF Configuration
9
SFF in Action
Description:
Dive deep into the implementation of the CNCF's Secure Software Factory reference architecture in this conference talk. Explore the holistic nature of supply chain security and discover how the reference architecture addresses the software provenance gap faced by many projects and organizations. Learn how cloud native tools, when properly configured and implemented, can enhance artifact trustworthiness and provide reliable provenance. Examine a system built on tools like Kyverno, Tekton, Chains, Spire, and Sigstore, and understand how they interconnect to create software meeting high SLSA levels. Gain insights into the Secure Software Factory's functionality, build environment, defaults, configuration, and practical application through an example build.

Putting the Supply Chain Pieces Together: A Deep Dive into the Secure Software Factory

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00