Software Signing for Kubernetes Supply Chain & Everybody Else
Software Signing for Kubernetes Supply Chain & Everybody Else

Software Signing for Kubernetes Supply Chain & Everybody Else

Quenn D

50 min
Knowledge
Play

Description

<p>In this episode of the Virtual Coffee with Ashish edition, we spoke with <strong>Luke Hinds</strong> (<a href="https://twitter.com/decodebytes" target="_blank">Luke<strong>'s Twitter</strong></a><a href="https://twitter.com/jimmesta?lang=en"><strong>)</strong></a><strong> </strong>the open source Sigstore project and how it is helping with software signing and protecting the software supply chain</p> <p>Episode ShowNotes, Links and Transcript on Cloud Security Podcast: <a href="https://www.cloudsecuritypodcast.tv/season-2/kubernetes-goat-vulnerable-by-design-madhu-akula">www.cloudsecuritypodcast.tv</a></p> <p><strong>Host Twitter: Ashish Rajan (</strong><a href="https://twitter.com/hashishrajan"><strong>@hashishrajan</strong></a><strong>)</strong></p> <p><strong>Guest Twitter: </strong>&nbsp;<strong>Luke Hinds</strong> (<a href="https://twitter.com/decodebytes" target="_blank">Luke<strong>'s Twitter</strong></a><a href="https://twitter.com/jimmesta?lang=en"><strong>)</strong></a><strong>&nbsp;</strong></p> <p><strong>Podcast Twitter </strong>- <a href="https://twitter.com/cloudsecpod"><strong>@CloudSecPod</strong></a><strong> </strong><a href="https://twitter.com/CloudSecureNews"><strong>@CloudSecureNews</strong></a></p> <p><strong>If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:</strong></p> <p>- <a href="https://www.instagram.com/cloudsecuritynews/"><strong>Cloud Security News&nbsp;</strong></a></p> <p><strong>- </strong><a href="https://www.cloudsecuritypodcast.tv/cloud-security-academy"><strong>Cloud Security Academy</strong></a></p> <p><strong>Spotify TimeStamp for Interview Questions</strong></p> <p>(00:00) Ashish's Intro to the Episode</p> <p>(01:39) <a href="https://snyk.io/csp">https://snyk.io/csp</a></p> <p>(05:21) What is the software supply chain and why is it important?</p> <p>(08:20) Common supply chain attacks in Kubernetes</p> <p>(09:53) Codecov attack</p> <p>(11:14 )Kubernetes and API</p> <p>(14:10) Vulnerability

Uploader

isla_wave

isla_wave

Software Signing for Kubernetes Supply Chain & Everybody Else - Listen Free | WowFM