GopherCon 2023: Understanding Supply Chain Threats with Static Analysis - Jess McClintock
With increasing rates of supply chain attacks and vulnerabilities, there is a need for greater visibility into what behaviors are present in a package’s dependencies. Each Go package has an implicit set of expected capabilities - for example, it would be unexpected for a numerical analysis package to require network access. I will present a CLI tool for Go that highlights privileged permissions in your package’s dependencies to prevent supply chain attacks and motivate secure coding practices within the ecosystem.
Видео GopherCon 2023: Understanding Supply Chain Threats with Static Analysis - Jess McClintock канала Gopher Academy
Видео GopherCon 2023: Understanding Supply Chain Threats with Static Analysis - Jess McClintock канала Gopher Academy
Комментарии отсутствуют
Информация о видео
25 февраля 2024 г. 4:52:04
00:17:26
Другие видео канала