Главная
Study mode:
on
1
Introduction
2
Agenda
3
The Supply Chain
4
Devils Pipeline
5
Supply Chain Confusion
6
Package Squad
7
Namespaces
8
namespace confusion
9
Timelines
10
NPM Audit
11
NPM Autofix
12
MPQ Autofix
13
Attack Examples
14
SCVs
15
Gitbook
16
Inventory
17
Software Composition Analysis
18
Software Package Data Exchange
19
Verification Standard 3
20
Traceability
21
Package Management
22
Component Analysis
23
Provenance Pedigree
Description:
Explore the critical topic of supply chain attacks in this NDC Security 2022 conference talk. Learn about various attack vectors targeting development pipelines, including shell script vulnerabilities, package typosquatting, and internal package name squatting on public repositories. Discover how simple settings can be exploited to hijack environments, potentially leading to severe consequences. Gain insights into protecting your CI/CD pipeline, understanding package management risks, and implementing effective security measures. Delve into topics such as Software Composition Analysis, Software Package Data Exchange, and the importance of traceability in maintaining a secure supply chain. Equip yourself with the knowledge to safeguard your development processes against increasingly common supply chain threats.

Protect Yourself Against Supply Chain Attacks

NDC Conferences
Add to list