
Software Signing for Kubernetes Supply Chain & Everybody Else
Cloud Security Podcast
00:00
Introduction
Software supply chain is the primary topic that people are interested in because of log 4 J and s bomb. We spoke about a software signing open source project called six store with multiple projects underneath it, one of them being cosign. If you wanted to make sure that the container used by the Kubernetes cluster that you're running is coming from a GitHub repository, which is from your organization, how would you do that today? This was a really important topic that I wanted to bring over.
Play episode from 00:00
Transcript


