Xmas came early! Spiffe/Spire community just fulfilled another one of my #softwaresupplychainsecurity wish list items! https://github.com/spiffe/spire/issues/3514 is closed! We can now attest to the AMI ids being used by nodes and write policies to enforce on their provenance. Big thanks to Guilherme and Andrew!
New research report by Google on software supply chain security
Perspectives on Security Volume One: Securing Software Supply Chains
#infosec #oss #SoftwareSupplyChainSecurity
https://services.google.com/fh/files/blogs/perspectives_on_security_volume_one_digital.pdf
#infosec #oss #SoftwareSupplyChainSecurity
In your opinion, what are the top three security risks in software supply chain ecosystem?
📷 talk at #LeadingCyberLadies #Toronto last month
#SoftwareSupplyChainSecurity #infosec #cybersecurity #devops #devsecops
#leadingcyberladies #toronto #SoftwareSupplyChainSecurity #infosec #cybersecurity #devops #devsecops
In your opinion, what are the top three security risks in software supply chain ecosystem?
📷 talk at #LeadingCyberLadies #Toronto last month
#SoftwareSupplyChainSecurity #infosec #cybersecurity #devops #devsecops
#leadingcyberladies #toronto #SoftwareSupplyChainSecurity #infosec #cybersecurity #devops #devsecops