The Secure Developer

Securing the future of DevOps and AI: real talk with industry leaders.

https://the-secure-developer.simplecast.com

subscribe
share






episode 127: Software Supply Chain Security - Key Terms, Players, And Projects You Need To Know About


This is Part 2 in our 4 part mini-series on software supply chain. This week we are focusing on key terms. players and projects you need to know about when it comes to software supply chain security. When we stop to think about the software running in our production environments, a large proportion of it is very likely open source. Are there effective mechanisms to truly understand and have visibility into all of these libraries? How do you ensure that these libraries are secure? To answer these questions, we feature input from Guy Podjarny, Lena Smart, Brian Behlendorf, Aeva Black, Emily Fox, Jim Zemlin, David Wheeler and Simon Maple as we dissect some key terms and promising projects in the software supply chain security space. Tuning in, you’ll learn what the term SBOM means, why the problem of securing the open-source pipeline is such a complex one, and what organizations like the Open Source Software Foundation (SSF) and Open Source Initiative (OSI) are doing to address it. We also introduce some key players that can provide you with assistance as you work to improve your own open-source security or software supply chain security posture. For all this and more, you won’t want to miss part two of The Secure Developer’s software supply chain security series!


fyyd: Podcast Search Engine
share








 February 13, 2023  41m