| title |
Automated Tools for Securing the Software Supply Chain |
| date |
2022 |
| authors |
Michael Brown |
Evan Sultanik |
Will Woodruff |
|
| conference |
ITEA Cybersecurity Workshop 2022 |
|
| resources |
| label |
path |
Slides |
Automated Tools for Securing the Software Supply Chain.pdf |
|
|
This presentation discusses the inherent challenges in securing the software supply chain and the shortcomings of existing approaches. It covers the motivation, design, and implementation of It-Depends and pip-audit, demonstrating how these tools can be used to generate SBOMs and provide insight into the security posture of a given software package.