►
From YouTube: CNCF SIG Security Supply Chain Security 2021-04-30
Description
CNCF SIG Security Supply Chain Security 2021-04-30
B
New
house,
a
new
new
new
orleans.
C
No
new
orientation,
I
finally
got
a
desk
put
together
yeah
it's
slowly,
making
my
way
closer
to
my
office.
B
It's
only
been
locked
down
for
a
number
of
months
but
hold
on
well.
C
Now,
like
I've
got
I'm
building
an
office
above
my
garage
and
we're
almost
done
mudding.
C
C
I'm
going
through
the
paper
trying
to
get
some
of
the
commentary
closed
out.
B
B
I
I
shot
past
the
golden
image,
but
I
wouldn't
ask:
maybe
it's
an
english
thing,
but
I've
always
referred
to
it
as
a
golden
image.
Genesis,
image
of
thing.
C
Yeah,
so
here's
the
deal-
and
this
is
me
trying
to
like
undo
decades
of
bad
practices.
So
the
concept
of
a
golden
image
is
traditionally
like
the
source,
the
thing
of
which
everything
else
occurs
and.
A
C
Usually
like
the
most
controlled,
you
can
use
it
as
an
independent
verification
tool
to
be
like
hey
or
at
least
within,
like
defense
systems.
You
have
this
team
that
produces
a
golden
image,
and
then
you
have
another
team
that
goes
through
a
similar
process
and
creates
a
deliverable
packaged
good,
and
then
you
compare
the
two
of
them,
so
any
deviations
from
that
from
the
packaged
good
that
are
different
than
the
golden
image
are
problematic.
C
So
it's
like
that
usually
like
when
I
hear
the
term
golden
image.
I
think
of
it's
this
thing
that
sits
on
a
pedestal
and
like
the
angel,
choirs
sing
and
there's
light
coming
down
from
the
heavens
on
it,
and
it's
like
you,
don't
touch
it.
The
problem
is:
is
that
a
lot
of
instances
where
golden
images
occur
as
the
source
of
truth?
They
often
go
unmaintained
so
like
once
an
organization
produces
this.
They
never
update
it,
because
it's
good,
we
don't
touch
it
and
that's
a
cultural
change.
B
Yeah,
do
we
need
to
explain
that
in
the
document
then,
because
that
that's
a
bit
of
a
change
to
the
way
I
use
the
term,
but.
C
I
get
his
concern.
I
think
it's
a
valid
concern,
because
it's
it's
very
overloaded.
I
try
to
avoid
golden
image
whenever
I
can,
because
there's
just
a
bad
history
there.
So
if
we
want
to
call
it
genesis
image
if
we
want
to
call
it
base
builder
image-
maybe
that's
maybe
that's
more
explicit
and
clear.
B
C
Well,
so
the
only
other
reference
I
think
that
we
have
is
in
that
same
section,
and
I
have
not
gone
through
and
done
a
control
f
on
this
is
the
build
environment,
consists
of
all
the
content
required
for
the
build,
including
the
sources
for
the
build
in
any
of
its
dependencies,
excluding
any
tooling
provided
by
the
build
image.
B
A
C
We're
genuinely
not
talking
about
a
golden
image
and
it's
traditional
sense
we're
talking
about
the
base
image
in
that
this
is
the
thing
that
is
not
part
of
your
software
product.
It's
not
part
of
the
end
result
of
what's
being
built.
It
is
an
ephemeral
object
that
is
spun
up,
serves
its
purpose
and
disappears.
B
Michael
alex,
you
know
any
any
thoughts.
You
know
what
we're
discussing
in
the
image
about
there's
a
section
on
page.
B
C
C
C
C
C
C
C
We
could
just
make
a
reference
to
the
rootless
container
site.
C
Which
has
articles
on
hold.
C
H
F
B
I'll
accept
that
other
comment
too
right.
Resultary.
C
B
C
Oh,
you
know
what
it
is
we
talked
about,
deterministic
builds,
so
I
think
it
just
needs
to
be
moved
around.
F
C
B
B
B
B
C
Okay,
I
think
I
got
rid
of
that
hanging
paragraph
there,
so
that
those-
if
you
accept
that
last
one
it
should
merge
everything.
C
C
G
A
C
H
C
C
B
A
C
B
What
the
hell!
Okay,.
C
Yeah
I
it's
been
killing
me
all
morning.
I
have
like
these
new
monitors
and
now
I
can
notice
spot
color
distinguishes
at
that
level.
Wow
yeah.
The
easiest
way
to
tell
is,
if
you
click
the
end
of
the
sentence
and
you
click
up
higher
in
the
paragraph.
If
the
little
text
color
icon
turns
white
like
it
indicates
that
there's
an
inconsistent
color
between
your
selection,
so
I've
changed
it
to.
B
Black,
well,
I
know
never
found
that.
That's
for
sure,
I'm
learning
all
sorts
of
new
things
about
google
docs
in
this.
This
journey,
I
tell
you
this
is
this
is
now
my
preferred
referred
editor.
B
G
B
B
Oh,
these
are
what's
going
on
here.
A
F
Feel
free
to
I
was
attempting
to
to
rewrite
it,
based
on
my
own
confusion
around
the
highlighted
part
from
how
it
was
originally
written,
but
like
feel
free
to
rip
into
it
and
change
it
around.
I
mean.
C
C
It's
like
there's
supposed
to
be
a
term
that
talks
about
like
minimal
functionality
and
like
separating
the
different
functional
components,
to
do
the
one
thing
that
they
do
well
and
encapsulate
them
such
that
they
do.
That
thing,
that's
that's
the
genesis
of
why
libraries
exist.
You
write
a
library
to
do
a
thing.
F
C
That
any
given
container
may
include
numerous
software
components
supplied
by
multiple
vendors.
So
I
think
the
clarity
here.
C
B
F
B
B
C
Shouldn't
slimming
container
images
be
heading
up.
B
C
C
I
think
we
start
with
a
issue
that
gets
submitted
to
the
cncf
service
desk
to
get
support
for
conversion
to
a
pdf
as
well
as
conversion
to
markdown.
We
need
to
clean
up
the
supply
chain,
part
of
the
repo
to
ensure
that
this
has
a
place
for
it,
because
I
don't
think
we
have
a
paper
section.
So
we
as
a
sig
need
to
decide
where
we're
putting
our
papers,
how
we're
managing
them
like
the
cloud
native
security
paper
is
a
general
one.
That's
fine
at
a
top
level,
but
a
supply
chain
paper.
C
We
already
have
a
supply
chain,
part
of
the
repo
it
might
make
sense
to
like
disentangle,
some
of
that,
so
that
maybe
somebody
should
drop
that
on
the
agenda
for
the
next
sig
meeting,
to
figure
out
what
it
is
that
we're
going
to
be
doing.
As
far
as
paper
management
within
the
sick,
yeah.
C
So
if
someone
could
add
to
next
sig
meeting
agenda
paper
management
because
we're
close
to
being
done,
I
will
attempt
sometime
this
week
to
contact
the
folks
that
I
worked
with
last
time
on
the
paper
to
figure
out
what
the
correct
process
is,
because
I
think
we
stumbled
through
things
last
time.
B
Longer
and
yeah
enjoyable,
but
enjoyable,
that's
for
sure,
cool.
All
right.