What We Discuss with Luke Hinds:
- 00:00 Introduction
- 05:31 What is the software supply chain and why is it important?
- 08:56 Common supply chain attacks in Kubernetes
- 10:48 The Codecov attack
- 12:08 Kubernetes and API
- 15:43 Vulnerability scanning tools
- 18:44 Explaining the importance of supply chain security
- 22:12 What is a signing service
- 23:06 The SLSA framework
- 23:59 Importance of signing service
- 27:35 What is sigstore?
- 32:43 Whats Lets Encrypt
- 37:25 The aim of sigstore
- 40:46 What is co sign?
- 43:00 Co-Signing and non-repudiation
- 54:25 Where to start
- 58:24 The Fun Section
THANKS, Luke Hinds!
If you enjoyed this session with Luke Hinds, let him know by clicking on the link below and sending him a quick shout out at Linkedin:
Click here to thank Luke Hinds at Linkedin!
Click here to let Ashish know about your number one takeaway from this episode!
And if you want us to answer your questions on one of our upcoming weekly Feedback Friday episodes, drop us a line at ashish@kaizenteq.com.