DevOps and Beyond

W23 Protect Yourself against Supply Chain Attacks

05/17/2023

4:00pm - 5:15pm

Level: Intermediate to Advanced

Rob Bos

DevOps Consultant

Xpirit

As an industry, we are using third party packages and building components for lots of things. In this supply chain, there are lots of places for vulnerabilities. They can then be used to attack your DevOps pipelines!

In this session, I will go over some common attack examples and show you a way to prevent them from happening. There are frameworks available in the industry that guide you through the process of becoming more mature in protecting not only your source code and application but also the packages you use and the pipelines you build them with. I'll demo some of GitHub's features that help preventing these types of attacks.

You will learn:

  • Why do we need to protect ourselves?
  • What things do we need to think about?
  • A framework to guide you through improving your security stance