Let's learn sigstore

Let's learn sigstore

Source: YouTube · Kubesimplify · published Nov 10, 2021 · 1:01:14

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

Supply chain security threats are increasing dramatically, with 64% of organizations reporting attacks in 2020, making tools like sigstore essential for verifying software integrity 00:02:30.

Key Takeaways:
• Supply chain attacks include typo-squatting, malicious code injection, and tool tampering, all targeting open source software dependencies 00:05:15
• Sigstore provides free code signing certificates and transparency logs to verify software authenticity and trace origins 00:12:45
• Cosign enables container image signing with both traditional key pairs and keyless certificates using OpenID Connect 00:18:20

The integration of sigstore with CI/CD pipelines like GitHub Actions and Tekton allows automated signing and verification throughout the software development lifecycle.

Sources:

  • 00:02:30 Introduction to supply chain security threats
  • 00:05:15 Types of supply chain attacks
  • 00:12:45 Sigstore project overview
  • 00:18:20 Cosign demonstration

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello everyone and uh welcome to day two of the cicd week uh my name is sam pathak and um i am a cncf ambassador working as a director of technical evangelism at cevo uh building the next gen cloud platform a lot of amazing things coming up uh so we should watch out that space uh just uh before we you know things get started people often ask me in every stream like you know uh what are the prerequisites do i need to know kubernetes and all that stuff so if you want to learn cube kubernetes plenty of resources out there uh the best one i recommend is the one that i created which is co academy free of cost so it is co.com academy uh no credit card required to learn all there are more than 50 plus video lectures that you can uh curated for kubernetes that you can learn i think that's pretty m…