Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx

Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx

0 Calificaciones
0
Episodio
115 of 121
Duración
29min
Idioma
Inglés
Formato
Categoría
No ficción

Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx

In this episode of the Security Repo Podcast, François Proulx, VP of Security Research at Boost Security, discusses the evolving threats in software supply chain security, particularly focusing on attacks targeting CI/CD pipelines. He explains how open source tools like "Poutine" are being used both defensively and offensively in the ongoing battle to secure build systems. François also shares his journey into security, lessons from working at Intel, and practical advice on dependency pinning, short-lived credentials, and password best practices.

https://www.linkedin.com/in/francoisp/

https://boostsecurity.io/blog/unveiling-poutine-an-open-source-build-pipelines-security-scanner

[https://nsec.io /](https://nsec.io/)

François is VP of Security Research at BoostSecurity, where he leads the Supply Chain research team. With over 10 years of experience in building AppSec programs for large corporations (such as Intel) and small startups he has been in the heat of the action as the DevSecOps movement took shape. François is one of founders of NorthSec and was a challenge designer for the NorthSec CTF.


Escucha y lee

Descubre un mundo infinito de historias

  • Lee y escucha todo lo que quieras
  • Más de 1 millón de títulos
  • Títulos exclusivos + Storytel Originals
  • Precio regular: CLP 7,990 al mes
  • Cancela cuando quieras
Suscríbete ahora
Copy of Device Banner Block 894x1036 3
Cover for Supply Chain Warfare: CI/CD Threats and Open Source Security with François Proulx

Otros podcasts que te pueden gustar...