

Securing the Software Supply Chain with LLMs
May 3, 2024
Feross Aboukhadijeh from Socket discusses using large language models to secure the software supply chain, overcoming challenges like the recent XZutils attack. They explore how AI tools can help identify risky packages, cut down on noise, and make security problems tractable. The conversation dives into the role of LLMs in scanning open source code, improving security maturity with NIST standards, and the evolving landscape of security against advanced attackers.
Chapters
Transcript
Episode notes
1 2 3 4 5 6
Introduction
00:00 • 3min
Challenges in Securing Software Supply Chains
02:58 • 13min
AI's Role in Improving Supply Chain Security
16:25 • 6min
Navigating the Complexities of the Software Security Market
21:59 • 2min
Enhancing Security Maturity with NIST Standards and AI Integration
23:57 • 4min
AI in Software Supply Chain Security
27:39 • 11min