GitHub-Azure Authentication and SLSA in DevOps with Marcel Lupo and Joshua Lock

Опубликовано: 01 Январь 1970
на канале: DevSecCon
137
4

Exciting news! DevSecCon London is hosting Marcel Lupo, Microsoft MVP, Cloud Solutions & DevOps Architect and technical speaker, and Joshua Lock, Open Source Software Supply Chain Security Architect at Verizon. Marcel will discuss GitHub Actions authentication methods for Azure, compares two approaches, and highlights the benefits of switching to a passwordless method using Open ID Connect (OIDC) and Joshua will introduce SLSA principles and their application in DevSecOps processes and systems, discusses the threat model guiding SLSA, explains SLSA's security levels, and provides insight into the open source project's future plans and how you can contribute.

Speakers:

Marcel Lupo, Microsoft MVP | Speaker | Cloud Solutions & DevOps Architect.
Marcel is a Microsoft MVP, Cloud Solutions & DevOps Architect and technical speaker focused on Microsoft technologies in the Azure cloud platform and specialises particularly in Automation, DevOps and Developer Technologies, with a strong focus on IaC, Azure DevOps and GitHub.
Marcel is passionate about technology and how it can be used in automation to bring value and solve complex business problems.
Regular speaker at conferences and meetups, and enjoy sharing knowledge and technical content with the wider tech community. Currently works at Avanade UK&I as a Group Manager for DevOps Engineering.

Joshua Lock, Open Source Software Supply Chain Security
Joshua is a versatile software engineer and open source professional with leadership roles in several open source projects. 15 years experience working on tools to build complex software systems deterministically and securely. He is passionate about building systems and software supply chain security.

Steering committee member and specification maintainer on the Supply-chain Levels for Software Artifacts (SLSA) project, The Update Framework (TUF) specification editor and implementation maintainer for python-tuf and go-tuf, contributor and root keyholder for Sigstore, friend of in-toto.

Emeritus core contributor to all aspects of OpenEmbedded and the Yocto Project.


Join the Community!

If you haven't joined the Discord community, please do so! You can find us on Discord at: https://devseccon.io/discordcommunity


Смотрите видео GitHub-Azure Authentication and SLSA in DevOps with Marcel Lupo and Joshua Lock онлайн без регистрации, длительностью часов минут секунд в хорошем качестве. Это видео добавил пользователь DevSecCon 01 Январь 1970, не забудьте поделиться им ссылкой с друзьями и знакомыми, на нашем сайте его посмотрели 137 раз и оно понравилось 4 людям.