CloudNativeSecurityCon 2023: How to Secure Software Supply Chain at Scale

At CloudNativeSecrityCon 2023 in Seattle, WA, Hamil Kadakia, and Yonghe Zhao, software engineers at Yahoo’s security team, presented on securing Software Supply Chain at Scale, and how to put together policies to safeguard against Supply Chain attacks. Kadakia started the talk by discussing what a software supply chain is and some of the common attacks such as injecting vulnerable dependencies, compromising artifacts, or altering privileges.

Read full article on InfoQ