Author: DigitalOcean - Bewertung: 0x - Views:9
Supply Chain Attacks are now becoming common, and one of the great examples was the NPM Great Heist which impacted 18 NPM packages with more than 2.5+ Billion Downloads weekly. Such attacks affect millions of developers and users, and can be really harmful for your business, application, and infrastructure.
If you're using npm, yarn, or any JavaScript package manager, you're at risk. Attackers are targeting open source dependencies, injecting malicious code, and stealing credentials through compromised packages.
In this video I'll share about:
• NPM's biggest supply chain attack in history and how it happened.
• What supply chain security is.
• Real-world preventions you can follow such as npm best practices, SBOM (Software Bill of Materials), SLSA framework, and Cosign for signing your containers.
• How to secure both your application and infrastructure from dependency attacks.
By the end of this video, you'll learn what supply chain security is, how to detect vulnerabilities using CVE databases, and how you can prevent such attacks on your codebase and Kubernetes clusters.
Whether you're a developer, DevOps engineer, or platform engineer, this video will help you ship more secure software.
// TIMESTAMPS ⏱️
00:00- Intro
00:40- Understanding NPM Great Heist Attack
01:46- What is Supply Chain Security
03:49- Types of Attacks
04:28- How to Prevent Attacks on Application Level
05:33- Understanding SLSA
06:36- How to check for known CVE
06:58- Understanding SBOM
08:48- Understanding Cosign Project
09:22- Conclusion
🚀 Join the Developer Cloud:
https://cloud.digitalocean.com/registrations/new?utm_source=youtube&utm_medium=organic_video&utm_campaign=digitalocean&utm_content=
// STAY CONNECTED
🌏 Follow our blog for the latest updates: https://www.digitalocean.com/blog
🦈 Join our Developer Community on Discord: https://discord.com/invite/digitalocean
🐥 Follow us on X/Twitter: https://x.com/digitalocean
👩💻 We're Hiring! See open roles: http://grnh.se/aicoph1