synopsis 2023 ossra report cyrc findings from 2022
11
supply-chain levels for software artifacts
12
dependency confusion attack - package mining
13
managing open source dependencies
14
the left-pad incident
15
container development
16
is there any hope???
17
what else can we do?
18
owasp resources cheat sheets
19
openssf trio of free courses
20
what can we do???
21
questions?
Description:
Explore security concerns throughout the software supply chain in this 36-minute conference talk from Conf42 DevOps 2024. Delve into topics such as security through obfuscation, the MoveIT transfer vulnerability, and the importance of developer education in coding safely. Examine software dependencies, including the Synopsis 2023 OSSRA report findings and supply-chain levels for software artifacts. Learn about dependency confusion attacks, package mining, and the infamous left-pad incident. Investigate container development challenges and discover hope through OWASP resources, OpenSSF courses, and actionable steps to improve security practices. Gain valuable insights to address vulnerabilities and strengthen your software development process from start to finish.
Security Concerns in Every Stage of the Software Supply Chain