Building Images For The Secure Supply Chain
GOTO Amsterdam 2023

Thursday Jun 29
11:20 –
12:10
Administratiezaal

Building Images For The Secure Supply Chain

Slides:


This video is also available in the GOTO Play video app! Download it to enjoy offline access to our conference videos while on the move.

Available in Google Play Store or Available in Apple App Store




Security scans getting you down? Is the security team complaining about the CVE count in your images? Want to improve your SLSA level but don't know where to start? You're not alone - all organisations face these issues. This talk will walk through techniques and tooling that you can use today to address these concerns. In particular it will cover:

  • how to reduce the CVE count in your images by minimising dependencies
  • the importance of updating images and dependencies
  • Using apko to build container images with SBOMs and complete reproducibility