About this talk
This session, led by Paolo Mainardi, explores the current state of the software supply chain, highlighting significant global events such as SolarWinds and log4shell. The speaker discusses the challenges facing the Open-Source ecosystem and presents various threats along with potential mitigations. By utilizing tools like Sigstore, Syft, and Grype for digital signatures, Software Bill of Materials (SBOM) generation, and automated vulnerability scanning, attendees learn how to enhance the integrity of their digital artifacts and improve insights into their cloud infrastructures.