Loading…
June 21-24, 2022
Austin, Texas, USA + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2022 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central Daylight Time (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

SupplyChainSecurityCon [clear filter]
Tuesday, June 21
 

2:05pm CDT

Lessons Learned from Automating SLSA-Compliance Evaluation - Daniel Nebenzahl, Scribe-security
SLSA (Supply-chain Levels for Software Artifacts) is a framework led by Google, that defines four levels of protection for a software supply chain, and provides guidelines on how to reach these levels. Since companies operate dynamic pipelines, there is a need to continuously measure the pipeline's security. This can be met by implementing automated SLSA-compliance evaluation. In this talk , we shall share lessons learned from our journey in implementing automation in real-world scenarios using open-source tools such as Sigstore and OPA. The lessons, conceptual and technical, shed light on the real-world details and challenges we encountered when evaluating, and automating the evaluation of SLSA compliance. Some of these lessons challenge part of SLSA requirements.

Speakers
avatar for Danny Nebenzahl

Danny Nebenzahl

CTO, Co-founder, Scribe Security
Danny is an established expert in cyber and crypto technologies. Previously a Lieutenant Colonel in Matzov - the Israel Defense Forces cyber defense center - where he led the research division for 11 years and was responsible for developing innovative cyber technologies. He was also... Read More →



Tuesday June 21, 2022 2:05pm - 2:45pm CDT
Brazos (Level 2)

2:55pm CDT

Road to SLSA3: Non-falsifiable Provenance in Tekton with SPIFFE/SPIRE - Parth Patel, IBM & Brandon Lum, Google
Tekton, a cloud native solution for building CI/CD systems, has made great strides in achieving SLSA Level 1 (​​unsigned provenance) and 2 (hosted source/build, signed provenance) with the inclusion of Tekton Chains. Part of attaining higher SLSA levels include protecting and holding the build systems we use accountable. A requirement of SLSA level 3 is non-falsifiable provenance, which states that build system provenance should not be falsifiable by build service’s users - i.e. protecting against cluster administrators. With the integration SPIFFE/SPIRE, Tekton can achieve this capability. SPIFFE/SPIRE provides Tekton with short-lived certificates (backed by workload attestation), that are used to sign build results and status updates (through the TaskRun object). This results in the ability to provide and verify provenance of the build steps, ensuring that they are cryptographically protected against edits not performed by the Tekton Trusted Computing Base (TCB). In this presentation we will show this in action and sabotage our own pipelines to visualize non-falsifiable provenance.

Speakers
avatar for Brandon Lum

Brandon Lum

Software Engineer, Google
Brandon loves designing and implementing computer systems (with a focus on Security, Operating Systems, and Distributed/Parallel Systems). Brandon is a Co-chair of the CNCF Security TAG, and as a part of Google's Open Source Security Team, he works on improving the security of the... Read More →
avatar for Parth Patel

Parth Patel

Co-Founder, Kusari
Solutions Architect with 10+ years of CyberSecurity, DevOps, Software Development and Automation experience. Parth has successfully led multiple consulting and development projects in various industries (regulated and commercial) for modernization/migration, cloud adoption and secure... Read More →



Tuesday June 21, 2022 2:55pm - 3:35pm CDT
Brazos (Level 2)
 
Wednesday, June 22
 

4:35pm CDT

Github Actions Security Landscape - Alex Ilgayev & Ronen Slavin, Cycode
Github Actions, the recent (from 2018) CI/CD addition to the popular source control system, is becoming an increasingly popular DevOps tool mainly due to its rich marketplace and simple integration. As part of our research of the Github actions security landscape, we discovered that in writing a perfectly secure Github actions workflow, several pitfalls could cause severe security consequences. Unless the developers are proficient in the depths of Github best-practices documents, these workflows would have mistakes. Such mistakes are costly - and could cause a potential supply-chain risk to the product. During the talk, we’ll walk you through our journey on how we found and disclosed vulnerable workflows in several popular open-source tools, delved into Github actions architecture to understand the possible consequences of these vulnerabilities, and present what could be the mitigations for such issues.

Speakers
avatar for Ronen Slavin

Ronen Slavin

Cycode, CTO
Ronen Slavin is Chief Technology Officer and co-founder of Cycode with expert knowledge in cybersecurity. Previously, he was the CTO and co-founder of Filelock that uniquely developed a solution to protect data even after a breach has occurred. Fileock was acquired by Reason Software... Read More →
avatar for Alex Ilgayev

Alex Ilgayev

Head of Security Research, Cycode
Alex Ilgayev is a security researcher specializing in software supply chain security vulnerabilities. At Cycode, he is responsible for hunting down security issues and researching possible mitigations. Before that, Alex led the malware research team at Check Point Research, where... Read More →



Wednesday June 22, 2022 4:35pm - 5:15pm CDT
Brazos (Level 2)
 

Filter sessions
Apply filters to sessions.
  • CloudOpen
  • Community Leadership Conference
  • ContainerCon
  • Critical Software Summit
  • Diversity Empowerment Summit
  • Embedded IoT
  • Embedded Linux Conference (ELC)
  • Emerging OS Forum
  • Global Security Vulnerability Summit (GSVS)
  • Keynote Sessions
  • LinuxCon
  • Open AI & Data Forum
  • Open Source On-Ramp
  • OSPOCon
  • Project Mini-Summits / Co-located Events
  • Special Events / Exhibits / Breaks
  • SupplyChainSecurityCon
  • Wildcard