logo

Episode 216: Signed, Sealed and Delivered: The Future of Supply Chain Security

ID: 178a4c1f-b7f8-5666-a325-ee45103e5a02

STIX ID: report--178a4c1f-b7f8-5666-a325-ee45103e5a02

Feed Name: Security Ledger

Date Published: 2021-06-10

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

This transcript of Security Ledger podcast episode 216 features an interview with Brian Trzupek (DigiCert) about securing the software supply chain. Topics include the role and correct implementation of digital code signing, shifting DevOps and tooling to improve identity and deployment controls, quorum-based deployment approvals, managing signing keys and audit trails, and producing software bills of materials; SolarWinds is cited as a cautionary example of a signed build compromised in the supply chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.