

DevOps Academy Deep Dive S1E13: Software Supply Chain Security — Can We Still Trust Open Source?
IA
DevOps Academy Podcast por Ivo Radulovski
T1 · E13
26 ago 2026
24:40
Notas del episodio
Modern software is built on open source—but how much do we really know about the code, packages, container images, and CI/CD components entering our production environments?
In this episode of DevOps Academy Deep Dive, we explore the growing challenge of software supply chain security and what DevOps teams can do to move from blind trust toward verifiable trust.
The conversation looks beyond vulnerability scanning to examine the entire path from source code to production—including dependencies, compromised packages, SBOMs, artifact provenance, signing, container security, CI/CD permissions, and the emerging impact of AI-generated code.
🔑 Key Takeaways
- Why software dependencies have become a major security challenge
- How compromised and malicious packages can e ...
Palabras clave
DevOps
DevOps Challenges
DevOps Engineer
DevOps Learning
DevOps Trends
Open Source Security
DevOps Security