
Kubernetes Podcast from Google
Software Supply Chain Security, with Priya Wadhwa
Jul 23, 2021 · 36 min · Episode 155 · 52.3 MB
0:00-36:18
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
The idea of software supply chain security rocketed into the public consciousness in the last year, with the news that US government agencies had been breached. Priya Wadhwa is a software engineer at Google working on open source security, including projects to secure and verify container deployments. She outlines what is being done to make sure this doesn't happen to you.
Do you have something cool to share? Some questions? Let us know:
- web: kubernetespodcast.com
- mail: kubernetespodcast@google.com
- twitter: @kubernetespod
- Google Cloud Container Security webinar
- Register for Google Cloud Next 2021
- Google Cloud IDS
- Windows Server support for Anthos on-prem
- Multi-Cluster Ingress for GKE
- CVE-2021-22555: Kernel code execution through Netfilter bug
- CVE-2021-25740: Endpoint & EndpointSlice permissions allow cross-Namespace forwarding
- CVE-2021-32690: Helm repository credentials passed to alternate domain
- Attacks on Argo Workflows discovered by Intezer
- Sysdig acquires Apolicy; Apolicy acquired by Sysdig
- CockroachDB Operator for Kubernetes
- Automatic remediation of Kubernetes nodes at Cloudflare
- CNCF App Delivery TAG publishes operator whitepaper
- Software supply chain
- Reproducible builds
- SolarWinds hack
- US Executive Order on Improving the Nation's Cybersecurity
- Binary Authorization
- Provenance, in art and software
- in-toto
- sigstore
- Tekton
- Tekton Chains
- Announcement blog, by Priya & Dan
- SBOM (Software Bill of Materials)
- Open Source Insights
- SLSA
- SupplyChainSecurityCon
- sigstore Slack channel
- Priya Wadhwa on Twitter
Priya Wadhwa
twitter.comkubernetespodcast.com
kubernetespodcast.com@kubernetespod
twitter.comVirgin Galactic launch
youtube.comNBC News
youtube.comBBC News
bbc.co.ukBlue Origin launch
youtube.comNBC News
youtube.comBBC News
bbc.co.ukThe memes
businessinsider.comGoogle Cloud Container Security webinar
cloudonair.withgoogle.comRegister for Google Cloud Next 2021
cloud.withgoogle.comGoogle Cloud IDS
cloud.google.comWindows Server support for Anthos on-prem
cloud.google.comMulti-Cluster Ingress for GKE
cloud.google.comCVE-2021-22555: Kernel code execution through Netfilter bug
google.github.ioSysdig acquires Apolicy
sysdig.comApolicy acquired by Sysdig
apolicy.ioCockroachDB Operator for Kubernetes
cockroachlabs.comAutomatic remediation of Kubernetes nodes at Cloudflare
blog.cloudflare.comSciuro
github.comKured
github.comSoftware supply chain
cloud.google.comKnow, Prevent, Fix
security.googleblog.comReproducible builds
reproducible-builds.orgDebian Project
wiki.debian.orgSolarWinds hack
en.wikipedia.orgBinary Authorization
cloud.google.comProvenance
en.wikipedia.orgin-toto
in-toto.io"Farm to table"
dl.acm.orgsigstore
sigstore.devAnnouncement blog
security.googleblog.comcosign
github.comAnnouncement blog
security.googleblog.comDan Lorenc's blog
blog.sigstore.devConnaisseur
github.comRekor
github.comFulcio
github.comDan Lorenc on Episode 152
kubernetespodcast.comAnnouncement blog
blog.sigstore.devVideo
twitch.tvTekton
tekton.devTekton Chains
github.comAnnouncement blog
security.googleblog.comSBOM (Software Bill of Materials)
en.wikipedia.orgOpen Source Insights
deps.devAnnouncement blog
opensource.googleblog.comNine Inch Nails' Year Zero ARG
en.wikipedia.orgScorecards
github.comAnnouncement blog
openssf.orgv2 blog
security.googleblog.comSLSA
slsa.devAnnouncement blog
security.googleblog.comGitHub
github.comSupplyChainSecurityCon
events.linuxfoundation.orgsigstore Slack channel
github.com