2conference talks

Software Supply Chain Security talks & resources

Hands-on guidance for SLSA, Sigstore and Cosign, build provenance, attestations, admission policy, and secure CI/CD.

Talks about Software Supply Chain Security

Open a session for the full abstract, implementation details, video, slides, and repositories.

November 15, 2024 · KubeCon + CloudNativeCon North America 2024

KubeCon CloudNativeCon North America 2024: Practical Supply Chain Security: Implementing SLSA Compliance from Build to Runtime

End-to-end implementation patterns for SLSA compliance using GitHub Actions, Cosign, Kyverno, in-toto, and Kubescape.

August 21, 2024 · KubeCon + CloudNativeCon + Open Source Summit China 2024

KubeCon CloudNativeCon China 2024: Securing the Supply Chain: A Practical Guide to SLSA Compliance from Build to Runtime | 保障供应链安全:从构建到运行的SLSA合规实用指南

A practical, beginner-friendly walkthrough of SLSA-focused supply chain security from build pipelines to Kubernetes runtime enforcement.