Company
Date Published
Author
Carlos Chang
Word count
1690
Language
English
Hacker News points
None

Summary

The JFrog swampUP 2023 conference highlighted key insights and transformative ideas for DevOps and DevSecOps practices, featuring presentations from industry leaders like John Willis, Brett Smith, and Tracy Ragan. John Willis emphasized the importance of Deming's System of Profound Knowledge for driving change in DevSecOps, focusing on breaking down silos and questioning the relevance of numerical goals. Brett Smith discussed securing the software supply chain in line with Executive Order 14028 and the SLSA framework, advocating for clear environment separation and automation to enhance security. Tracy Ragan introduced a new generation of open-source security tools aimed at securing the DevOps pipeline across its five phases, suggesting tools for code signing, build actions, post-build efforts, publishing, and auditing. The conference encouraged attendees to rethink traditional practices, embrace automation, and adopt comprehensive security measures to safeguard the evolving software landscape.