HowToSecureSupplyChain_2023.pdf

编号:140608 PDF 28页 3.13MB 下载积分:VIP专享
下载报告请您先登录!

HowToSecureSupplyChain_2023.pdf

1、Hemil Kadakia&Yonghe Zhao,YahooSecure your Software Supply Chain at ScaleAgenda What is software supply chain&why is it important?Existing solutions Infrastructure&Scale at Yahoo!Demos&deep dive Lessons learnedWhat is the software supply chain?Everything it takes to produce your softwareWhat is the

2、problem?Why is it important to us?Recent studies 85 to 97%of enterprise codebase uses open source software Three out of Five Companies Targeted-Anchore 62%of Organizations Have Been Impacted by Software Supply Chain Attacks-AnchoreAnchores software supply chain security reportSonatypes state of the

3、software supply chainExisting standards/tools.Additional reading:TAG Security ResourcesButCurrent State at Yahoo!60k daily builds and 5k images published per day.700+K8s clusters and 100k+pods running.Many tooling choices at each step of SDLC!Choose your battles wiselyExisting security controls Stat

4、ic code scanning.GitHub branch protection&2 PR reviewers.MFA&SSH keys for GitHub operations.Ephemeral creds in build environment.Mirror external registry.Starting our journeySoftware Composition Analysis(SCA)SCA checks only vulnerabilities in open source dependencies.97%of open source vulnerabilitie

5、s can be fixed by updating to the latest version.Auto remediation of security vulnerabilities.Build time vuln assessmentProduction deployment verification Image provenance check.Image signature check.Image freshness check.Image provenance checkProvenance:records that tell you where this image comes

6、from.Provenance helps us to ensure images are:built from only allowed repo/branch/tag built using supported CI/CD pipelines Demo:provenance checkNote:All Yahoo internal host names and image names has been sanitized for all demos.Image signature check Signature

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(HowToSecureSupplyChain_2023.pdf)为本站 (2200) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠