Secure Container Supply Chains Discussion @RedHatOpen
Secure Container Supply Chains Discussion  @RedHatOpen
Uploaded April 2021 | Updated September 2026, 1 hour ago
Presenters: Nisha Kumar, VMware, Brandon Lum, IBM, Steve Lasker, Microsoft, Louis DeLosSantos, Red Hat



Securing the Software Supply Chain has rapidly become a top concern for Open Source communities. There are many initiatives, most notably, the work by GitHub, to track and audit source code dependencies. However, this level of scrutiny is not applied when building container images, even though the resulting artifact is the product of various software supply chains, from the base OS’s package manager to the system dependencies required to make the top level application work. There are currently several projects trying to address the specific concerns of securing the supply chain for containers. These include the work of Notary V2, In-toto, OCI Artifacts, and Tern, in conjunction with the work of the CNCF’s SIG-Security Secure Supply Chain Security Working Group. Come join the discussion on how these projects may facilitate Open Source communities securing their container builds, and address any gaps that are currently present.
Secure Container Supply Chains DiscussionRed Hat NEXT! 2022: The Evolution of ComputePost-Flock 2026 Roundup - 2026-06-24Community Central: Performance Co-PilotUpstream: A Conversation about the Foreman ProjectCommunity Central: Intro to Ceph: Open Source Distributed Storagellm-d 101: Why Do We Need It?Red Hat NEXT! 2022: Enabling Next Generation Networking with eBPFWhy AI Infrastructure Must Be Built in the OpenGetting Started with Inference Using vLLMCommunity Central: Using Pulp 3 - Simpler and FasterCoreOS vs Fedora IoT
Red Hat Open |

Secure Container Supply Chains Discussion

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER