Adrian Mouat 12/27/2022

Building images for the secure supply chain

Read Original

This article, based on a CloudNativeSecurityCon presentation, discusses best practices for securing the software supply chain by building secure container images. It emphasizes signing images with Sigstore/cosign, reducing vulnerability scanner noise by minimizing dependencies, and the future role of Software Bills of Material (SBOMs) for identifying exposures.

Building images for the secure supply chain

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser