Loading…
Attending this event?
September 30 - October 1, 2024 | New York, New York
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source in Finance Forum New York 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Savings Time (EDT). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Monday September 30, 2024 2:30pm - 3:00pm EDT
In this talk, we will discuss the Sigstore, Enterprise Contract, and GUAC projects, and how they help mitigate risks in the software supply chain.
Consuming open source is only a risky proposition if you don’t take the time to engineer a process that mitigates risk through security best practices of open source. Building a program for your organization to securely consume and contribute to open source is no different than developing new software. It is entirely determined by the practices, policies, technical controls, risk tolerance, and culture you establish and reinforce. From your software supply chain to your running services, open source can be both a reference and a guide to conducting the necessary diligence so that your investment in open source is a reward for you, your engineers, and your business. In this talk, we’ll explore assumptions about open source and open source security, tactics for managing secure open source consumption, reducing or mitigating risk presented by open source, and how to successfully use triangle composition to drive your efforts.
Speakers
avatar for Veda Shankar

Veda Shankar

Senior Principal Product Manager in the Application Developer BU, Red Hat
Veda manages the Trusted Application Pipeline and Trusted Artifact Signer products. Trusted Artifact Signer is a production-ready deployment of the Sigstore service within an enterprise. With over 10 years of experience with Red Hat's products, Veda has performed multiple roles, from... Read More →
Monday September 30, 2024 2:30pm - 3:00pm EDT
Music Box
Log in to leave feedback.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link