Securing the Supply Chain - Automating our Way Out of Security Whack-a-Mole

Logo
Presented by

Mackenzie Jackson - Security Advocate at GitGuardian

About this talk

Open-source components forever changed how we build software, but they are also a prominent security threat, nothing illustrated this better than the recent XZ library incident where the world narrowly avoided a massive supply chain attack. Join Gene Gotimer, DevOps Engineer at Praeses and Mackenzie Jackson to discuss how we can keep our open-source supply chains secure as we discuss: - Security implications of vulnerable open-source components - How using automation can help us move toward a secure supply chain - How to discover and detect vulnerable components
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (34)
Subscribers (656)
Learn how software-driven organizations use GitGuardian to strengthen their overall security posture and comply with application security frameworks and standards. GitGuardian, founded in 2017, has become the leader in automated secrets detection and is now focused on providing a comprehensive code security platform. It's raised $56M from top investors, including co-founders of GitHub and Docker. Its policy engine helps security teams monitor and enforce rules across all their VCS, DevOps tools, and infrastructure-as-code configurations. GitGuardian offers Secrets Detection, Infra as Code Security, and Honeytoken capabilities all in one platform.