Skip to main content

Enhancing artifact security with GitHub Artifact Attestations

UB4.132 | Day 1 | 18:30 - 19:00 | Speakers: Fredrik Skogman

Enhancing artifact security with GitHub Artifact Attestations
A picture of a devroom at FOSDEM 2024

Stream opens at 18:30 (Europe/Brussels)

Notes

Abstract

In the evolving landscape of software development, ensuring the integrity of build artifacts like container images is crucial. GitHub Artifact Attestations is an artifact signing solution and PKI built on open source software like TUF and Sigstore. In this talk, I'll discuss and demonstrate how to use Artifact Attestations to generate signed SLSA attestations, and verifying their origin and authenticity. By the end of this session, you'll have a good understanding of how open source tools like Sigstore, in-toto, SLSA and TUF can collectively strengthen the security of the software supply chain.

Attachments

Speakers

Fredrik Skogman

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.