BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.cfgmgmtcamp.org//ULJAJM
BEGIN:VTIMEZONE
TZID:Europe/Brussels
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2023-ULJAJM@cfp.cfgmgmtcamp.org
DTSTART;TZID=Europe/Brussels:20230207T140000
DTEND;TZID=Europe/Brussels:20230207T145000
DESCRIPTION:Infrastructure management tools have a special place among soft
 ware regarding security\, as they usually run ubiquitously\, with high pri
 vileges and a relatively high attack surface. This makes them targets of c
 hoice\, especially in the current context of increased threats on software
  supply chains.\n\nWhat are our (new) responsibilities as software editors
  in an open source ecosystem? They include a precise identification and au
 thentication of all software components (to provide a Software Bill of Mat
 erial) and constraints on the build process and software distribution mode
 ls. \n\nThis talk will give an overview of the current state of the rapidl
 y evolving software supply chain standards and tooling (e.g. SLSA\, SBOMs\
 , etc.). It will also explore more concrete items\, focused on dependencie
 s management in open source ecosystems and our experience with Rudder.
DTSTAMP:20260913T134708Z
LOCATION:B.3.037
SUMMARY:Securing the software supply chain for Infra management tools - Ale
 xis Mousset
URL:https://cfp.cfgmgmtcamp.org/2023/talk/ULJAJM/
END:VEVENT
END:VCALENDAR
