Delivering Software

Fast

Security Engineers

Keep Things Safe

OpenSource Software

Free Software

Cloud is Secure

By Default

Right ???

Security is a Practice

It's not All or Nothing

Always Evolving

Fundamentals

https://landscape.cncf.io/

Dependencies

Dependencies

Dependencies

require (
	dario.cat/mergo v1.0.1 
	github.com/Masterminds/goutils v1.1.1 
	github.com/Masterminds/semver/v3 v3.3.0 
	github.com/Masterminds/sprig/v3 v3.3.0 
	github.com/coder/websocket v1.8.12 
	github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc 
	github.com/emicklei/go-restful/v3 v3.12.0 
	github.com/fsnotify/fsnotify v1.7.0 
	github.com/gabriel-vasile/mimetype v1.4.5 
	github.com/go-logr/logr v1.4.2 
	github.com/go-openapi/jsonpointer v0.21.0 
	github.com/go-openapi/jsonreference v0.21.0 
	github.com/go-openapi/swag v0.23.0 
	github.com/go-playground/locales v0.14.1 
	github.com/go-playground/universal-translator v0.18.1 
	github.com/go-playground/validator/v10 v10.22.1 
	github.com/go-resty/resty/v2 v2.15.3 
	github.com/gogo/protobuf v1.3.2 
	github.com/golang/protobuf v1.5.4 
	github.com/google/gnostic-models v0.6.8 
	github.com/google/go-cmp v0.6.0 
	github.com/google/gofuzz v1.2.0 
	github.com/google/uuid v1.6.0 
	github.com/gosimple/slug v1.14.0 
	github.com/gosimple/unidecode v1.0.1 
	github.com/hashicorp/go-cleanhttp v0.5.2 
	github.com/hashicorp/go-retryablehttp v0.7.7 
	github.com/hashicorp/hcl v1.0.0 
	github.com/hasura/go-graphql-client v0.13.1 
	github.com/huandu/xstrings v1.5.0 
	github.com/imdario/mergo v0.3.16 
	github.com/inconshreveable/mousetrap v1.1.0 
	github.com/josharian/intern v1.0.0 
	github.com/json-iterator/go v1.1.12 
	github.com/leodido/go-urn v1.4.0 
	github.com/magiconair/properties v1.8.7 
	github.com/mailru/easyjson v0.7.7 

How do security scanning tools work?

How OpsLevel security integrations work?

Not All - But Common Ones

Push Vs Pull

Demo

What is the Future

https://slsa.dev/

They've built a framework with levels ...

What if we could codify it for others ...

Secure Software Supply Chains

By Kyle Rockman

Secure Software Supply Chains

  • 137