InfoQ Homepage Software Supply Chain Content on InfoQ
-
Tracy Miranda on Secure Supply Chains, SBOMs, and SLSA
In this episode, Tracy Miranda, a leader in the secure software supply chain domain, sat down with InfoQ podcast co-host Daniel Bryant and discussed the current state of the industry. Topics covered included the benefits of SBOMs and SLSA, getting started with generating SBOMs, and how developers should work with leadership when evaluating their organization’s security posture.
-
Kim Lewandowski and Michael Lieberman on Securing the Software Supply Chain with SLSA
Charles Humble talks to Kim Lewandowski and Michael Lieberman about the SLSA framework. They discuss why the software supply chain is under growing attack, explore the key ideas in SLSA and its connection to Google’s Binary Authentication for Borg, and think about how the framework might evolve.