DSO Overflow

S4Ep9 - Open Source Integrity with Luke Hinds


Listen Later

DSO Overflow S4EP9

Open Source Integrity
with
Luke Hinds

In this month's episode, Jessica and Glenn chatted with Luke Hinds to discuss topics around Open Source integrity and provenance.

Luke is a co-founder and the CTO at Stacklok who loves building open source software and communities, as well as leading talented engineering teams to develop innovative cutting edge security technologies at scale.

In this episode, Luke talks about the challenges of ensuring open source software integrity and provenance using cryptographic technologies and automated signing of software within the CICD pipeline using a non-profit software cryptographic signing service. He talks about managing developer expectations and how security should enable software development. We briefly discuss the dangers of putting too much trust into AI and the data that supports GenAI models.

Resources mentioned in this podcast:

  • Luke Hind's LinkedIn profile
  • Stacklok on LinkedIn
  • Stacklok's website
  • sigstore on LinkedIn
  • sigstore website
  • slsa website
  • Minder website
  • Minder on GitHub

DSO Overflow is a DevSecOps London Gathering production. Find the audio version on all good podcast sources like Spotify, Apple Podcast and Buzzsprout.

This podcast is brought to you by our sponsors:  Prisma Cloud, Tigera and Apiiro

Your Hosts
Steve Giguere linkedin.com/in/stevegiguere
Glenn Wilson linkedin.com/in/glennwilson
Jessica Cregg linkedin.com/in/jessicacregg

...more
View all episodesView all episodes
Download on the App Store

DSO OverflowBy Glenn Wilson, and Steve Giguere


More shows like DSO Overflow

View all
Darknet Diaries by Jack Rhysider

Darknet Diaries

7,818 Listeners