Open source software is a massive contribution that provides everything from foundational frameworks to tiny single-purpose libraries. We walk through the dimensions of trust and provenance in the software supply chain with Janet Worthington. And we discuss how even with new code generated by LLMs and new terms like slopsquatting, a lot of the most effective solutions are old techniques.
Resources
- https://www.forrester.com/blogs/make-no-mistake-software-is-a-supply-chain-and-its-under-attack/
- https://www.forrester.com/report/the-future-of-software-supply-chain-security/RES184050
Show Notes: https://securityweekly.com/asw-343
Fler avsnitt av Security Weekly Podcast Network (Audio)
Visa alla avsnitt av Security Weekly Podcast Network (Audio)Security Weekly Podcast Network (Audio) med Security Weekly Productions finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
