Phil Estes, Principal Engineer at Amazon Web Services (AWS), explains why container security extends far beyond using minimal images.
He emphasizes examining the entire supply chain including dependencies, software composition analysis, and software bill of materials (SBOM).
He discusses the importance of image signing, package signing, and certificate management initiatives, including the OpenSSF's work providing maintainers with physical keys for proper package signing.
Watch the full interview: https://ku.bz/K4LmmL2NN
This interview is a reaction to Harsha Koushik's episode https://ku.bz/n_sJ04xMY
Post #1514
285
Forwarded from KubeFM