DiscoverTalk Python To Me#457: Software Supply Chain Security with Phylum
#457: Software Supply Chain Security with Phylum

#457: Software Supply Chain Security with Phylum

Update: 2024-04-19
Share

Description

We've spoken previously about security and software supply chains and we are back at it this episode. We're diving in again with Charles Coggins. Charles works at a software supply chain company and is on to give us the insiders and defender's perspective on how to keep our Python apps and infrastructure safe.



Episode sponsors



Sentry Error Monitoring, Code TALKPYTHON

Mailtrap

Talk Python Courses



Links from the show



Series: How Malicious Python Code Gains Execution: blog.phylum.io



Pick a Python Lockfile and Improve Security: blog.phylum.io

Bad Beat Poetry: blog.phylum.io

PEP 665 – A file format to list Python dependencies for reproducibility of an application: peps.python.org

PEP 517 – A build-system independent format for source trees: peps.python.org

PEP 518 – Specifying Minimum Build System Requirements for Python Projects: peps.python.org

Lockfiles should be committed on all projects: classic.yarnpkg.com

An Overview of Software Supply Chain Security: tldrsec.com

Typosquatting: docs.phylum.io

Common Attack Pattern Enumeration and Classification: capec.mitre.org

Dependency Confusion: docs.phylum.io

Expired Author Domains: docs.phylum.io

Unverifiable Dependency: docs.phylum.io

Repo Jacking: Hidden Danger in Broken Links: blog.phylum.io

Software Libraries Are Terrifying: medium.com

phylum 0.43.0: pypi.org

linguist: github.com

rich-codex ⚡️📖⚡️: ewels.github.io

Phylum Community Discord: discord.gg

The dream is dead?: mastodon.social

When "Everything" Becomes Too Much: The npm Package Chaos of 2024: socket.dev

pip-tools: github.com

Watch this episode on YouTube: youtube.com

Episode transcripts: talkpython.fm



--- Stay in touch with us ---

Subscribe to us on YouTube: youtube.com

Follow Talk Python on Mastodon: talkpython

Follow Michael on Mastodon: mkennedy
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

#457: Software Supply Chain Security with Phylum

#457: Software Supply Chain Security with Phylum

Michael Kennedy (@mkennedy)