What is the secure software supply chain and the current state of the PHP and Drupal ecosystem
About this talk
This talk presents the current state of the software supply chain, highlighting significant global events such as SolarWinds and log4shell. The speaker discusses the threats facing the PHP and Drupal ecosystem and explores various mitigation strategies using tools like Sigstore, Syft, and Grype, which enable digital signatures, SBOM generation, and automatic vulnerability scanning. The session includes a demonstration of these tools in action, showcasing their implementation in creating a secure supply chain pipeline for Drupal projects.