当前位置:首页 > 报告详情

HowToSecureSupplyChain_2023.pdf

上传人: 2*** 编号:140608 2023-08-31 28页 3.13MB

1、Hemil Kadakia&Yonghe Zhao,YahooSecure your Software Supply Chain at ScaleAgenda What is software supply chain&why is it important?Existing solutions Infrastructure&Scale at Yahoo!Demos&deep dive Lessons learnedWhat is the software supply chain?Everything it takes to produce your softwareWhat is the

2、problem?Why is it important to us?Recent studies 85 to 97%of enterprise codebase uses open source software Three out of Five Companies Targeted-Anchore 62%of Organizations Have Been Impacted by Software Supply Chain Attacks-AnchoreAnchores software supply chain security reportSonatypes state of the

3、software supply chainExisting standards/tools.Additional reading:TAG Security ResourcesButCurrent State at Yahoo!60k daily builds and 5k images published per day.700+K8s clusters and 100k+pods running.Many tooling choices at each step of SDLC!Choose your battles wiselyExisting security controls Stat

4、ic code scanning.GitHub branch protection&2 PR reviewers.MFA&SSH keys for GitHub operations.Ephemeral creds in build environment.Mirror external registry.Starting our journeySoftware Composition Analysis(SCA)SCA checks only vulnerabilities in open source dependencies.97%of open source vulnerabilitie

5、s can be fixed by updating to the latest version.Auto remediation of security vulnerabilities.Build time vuln assessmentProduction deployment verification Image provenance check.Image signature check.Image freshness check.Image provenance checkProvenance:records that tell you where this image comes

6、from.Provenance helps us to ensure images are:built from only allowed repo/branch/tag built using supported CI/CD pipelines Demo:provenance checkNote:All Yahoo internal host names and image names has been sanitized for all demos.Image signature check Signature

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了Yahoo在软件供应链安全方面的实践和经验。首先,文章阐述了软件供应链的定义及其重要性,指出企业代码库中有85%至97%使用了开源软件,并强调软件供应链攻击对组织的 Impact。其次,文章概述了现有的软件供应链安全解决方案和工具,包括静态代码扫描、GitHub分支保护、多因素认证等。然后,文章详细介绍了Yahoo在软件供应链安全方面的现状,包括每日构建次数、容器镜像数量等。最后,文章分享了Yahoo在软件供应链安全方面的实践经验,包括软件组件分析、镜像签名检查、镜像新鲜度检查等,并强调了持续反馈、自动改进开发者工作流程、提前规划采用和执行、项目可见性以及拥抱开源技术的重要性。
"软件供应链安全为何重要?" "雅虎如何实现软件供应链的规模化安全?" "如何通过软件供应链分析自动化修复安全漏洞?"
客服
商务合作
小程序
服务号
折叠