Skip to content

Details

Join us for the nineteenth Google Open Source Live event in our series; “Security Day 2022”!

Google Security experts will share updates on everything from Tooling to Help Secure Open Source Supply Chain, to Digital Signatures 101 and Sigstore.

Throughout the event, our speakers will answer selected questions via the Live Q&A Forum. We’ll wrap up the event with an After Party.

Event:
Security Day 2022 on Google Open Source Live

Date:
Thursday, May 5th from 9:00 am - 11:00 am PST

Agenda:
9:00 am
Opening for Security Day 2022 on Google Open Source Live
Alexandra Bush, Head of Open Source Marketing - Google Cloud (Google)
Nicky Ringland, Product Manager (Google)

9:02 am
Session 1: Tooling to Help Secure Open Source Supply Chain
Open source demand continues to explode, representing a 73% YoY growth in developer downloads of open source components. Yet, even though projects have their code open-source, the security practices used to run, test, release, and maintain these are less known. Scorecards is a tool that inspects and evaluates the open source projects’ adherence to security best practices, and it can help evaluate the software you depend on. Allstar is a tool to keep your own GitHub projects’ practices secure as well. In this talk, learn about these two tools, developed by the OpenSSF.
Jeff Mendoza, Software Engineer (Google)
Laurent Simon, Security Engineer, Google Open Source Security Team (GOSST) (Google)

9:17 am
Session 2: After Advisory: Dependencies Post Disclosure
Zero-days vulnerabilities in dependencies can send open source maintainers into a flurry of activity, and enterprise into panic, but what happens after the fact? We’ll take an ecosystem view of some recent high-profile advisories and assess how individual contributions as well as language features impact vulnerability mitigations.
Nicky Ringland, Product Manager (Google)

9:38 am
Session 3: Improving your Software Supply Chain Security Moves with SLSA on Github Actions
Software Supply Chains have become an increasingly popular target for attackers in recent years. The Supply Chain Levels for Software Artifacts (SLSA) framework aims to help ensure your software builds are secure from source to production. In this session we will discuss how to use SLSA with Github Actions to sign builds with sigstore and verify it in your production environment.
Ian Lewis, Developer Advocate (Google)

9:58 am
Session 4: Digital Signatures 101 and Sigstore
Code signing is the foundation of authenticating software artifacts. In this talk, we'll explore what a digital signature is (and what it isn't!), problems around key management, and how projects like Sigstore can help.
Asra Ali, Software Engineer (Google)

10:22 am After Party

11:00 am End

Reasons why you should attend this virtual event LIVE:

  1. Selected questions will be answered by our speakers in real time! The Live Q&A Forum will be open during the event from 9:00 am to 10:22 am PST.
  2. Join in on the after party fun, where you can participate in an exciting quiz, and hear from our speakers and emcees immediately following the event!

Related topics

New Technology
Web Development

You may also like