
DevOps Paradox DOP 239: What's in Your From Line? A Conversation With Chainguard
Nov 29, 2023
Ville Aikas and Matt Moore from Chainguard discuss open-source projects, distroless containers, and software security. They talk about improving vulnerability scanners, the significance of the APK format, and maintaining vulnerability-free software environments with Wolfi. They also explore the concepts of static linking in containerization and keyless signing for identity resolution.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8
Introduction
00:00 • 2min
Exploring Identity and Introducing Chaingard: A Discussion on Software Security
01:35 • 2min
Background and Start of Chainguard Company
03:05 • 4min
Static Linking in Containerization
07:17 • 18min
Security Scanning and Reliability of ChainGuard's Open-Source Projects
25:30 • 2min
Alignment with Open Source and Licensing Changes
27:21 • 7min
SIGSTOR: Keyless Signing and Identity Resolution
34:00 • 4min
Keyless verification and minimal container runtimes
37:47 • 6min
