DiscoverDSO OverflowS5Ep1 - Securing the Software Supply Chain with Francois Proulx
S5Ep1 - Securing the Software Supply Chain with Francois Proulx

S5Ep1 - Securing the Software Supply Chain with Francois Proulx

Update: 2025-01-31
Share

Description

DSO Overflow S5EP1

Security the Software Supply Chain
with
Francois Proulx

In this episode, featuring Francois Proulx, a senior product security engineer, we discuss software supply chain security, particularly the security of build pipelines and dependencies. Francois shares insights on defining supply chains, identifying vulnerabilities, threat modeling, and strategies to improve security. The conversation explores topics like the SALSA framework, risk factors in CI/CD pipelines, and reducing complexity in dependencies. The discussion emphasizes threat awareness, holistic approaches, and the importance of isolating critical processes in software development. Practical tools and insights on research and AI’s role in security were also touched upon.

Resources mentioned in this podcast:

DSO Overflow is a DevSecOps London Gathering production. Find the audio version on all good podcast sources like Spotify, Apple Podcast and Buzzsprout.

This podcast is brought to you by our sponsors:  Prisma Cloud, Tigera and Apiiro

Your Hosts
Steve Giguere linkedin.com/in/stevegiguere
Glenn Wilson linkedin.com/in/glennwilson
Jessica Cregg linkedin.com/in/jessicacregg

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

S5Ep1 - Securing the Software Supply Chain with Francois Proulx

S5Ep1 - Securing the Software Supply Chain with Francois Proulx