

DevOps Academy Deep Dive S1E13: Software Supply Chain Security — Can We Still Trust Open Source?
IA
DevOps Academy Podcast di Ivo Radulovski
S1 · E13
26 ago 2026
24:40
Note sull'episodio
Modern software is built on open source—but how much do we really know about the code, packages, container images, and CI/CD components entering our production environments?
In this episode of DevOps Academy Deep Dive, we explore the growing challenge of software supply chain security and what DevOps teams can do to move from blind trust toward verifiable trust.
The conversation looks beyond vulnerability scanning to examine the entire path from source code to production—including dependencies, compromised packages, SBOMs, artifact provenance, signing, container security, CI/CD permissions, and the emerging impact of AI-generated code.
🔑 Key Takeaways
- Why software dependencies have become a major security challenge
- How compromised and malicious packages can e ...
Parole chiave
DevOps
DevOps Challenges
DevOps Engineer
DevOps Learning
DevOps Trends
Open Source Security
DevOps Security