youtube image
From YouTube: Completely Securing the Software Supply Chain using Grafeas + in-toto - Lukas Puehringer


Want to view more sessions and keep the conversations going? Join us for KubeCon + CloudNativeCon North America in Seattle, December 11 - 13, 2018 ( or in Shanghai, November 14-15 (

Completely Securing the Software Supply Chain using Grafeas + in-toto - Lukas Puehringer, NYU & Wendy Dembowski, Google (Any Skill Level)

Continuous delivery, a prevalent concept in the cloud-native ecosystem, has drastically simplified and accelerated development and deployment of software from its inception to the end-user. Unfortunately, the continuous delivery supply chain has become an attractive target for attacks. An attacker that compromises any of the steps of the supply chain, or alters the product in transit, can target all users at once. In this talk Wendy Dembowski and Lukas Puehringer will introduce in-toto and grafeas(, a software supply chain security ecosystem to verify the supply chain integrity, authenticity, and compliance of any application. The talk will feature real-life examples, such as the target deployments for various popular projects, including Debian, Arch Linux, reproducible builds, and Docker.

About Wendy
Wendy is a Staff Software Engineer at Google. She is a co-founder and the Khaleesi of Grafeas.

About Lukas
Lukas Puehringer is a research scholar and developer at NYU's Center for Cyber Security (CCS), where he leads, the development of in-toto and has been co-maintaining several of Prof. Justin Cappos' software projects, such as the Seattle and Sensibility Network Testbeds and The Update Framework (TUF). Lukas presented in-toto and TUF at DebConf2017.
Join us for KubeCon + CloudNativeCon in Barcelona May 20 - 23, Shanghai June 24 - 26, and San Diego November 18 - 21! Learn more at The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy and all of the other CNCF-hosted projects.

Join us for KubeCon + CloudNativeCon in San Diego November 18 - 21. Learn more at The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy and all of the other CNCF-hosted projects.