Artwork

Content provided by open.intel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by open.intel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!
icon Daily Deals

Balancing Act: Software Security and Developer Experience

25:32
 
Share
 

Manage episode 472469494 series 3446189
Content provided by open.intel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by open.intel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode, we sit down with Luke Hinds, CTO of Stacklok and creator of Sigstore, to learn from his extensive background in open source security. Luke shares insights into his journey and passion for security, highlighting the thrill of the 'cat and mouse' dynamics. He discusses Stacklok’s project, Minder, a software supply chain platform designed to streamline security while boosting developer productivity. Luke also touches on Trusty, another Stacklok initiative aimed at assessing the security risks of open source packages using data science. The conversation expands to the impact of AI on code contributions and developer identity, reflecting on the evolving dynamics in software development and security. Finally, Luke shares thoughts on the ongoing challenges and opportunities in bridging the gap between operations and engineering to maintain robust security in fast-paced development environments.

00:00 Introduction

02:29 Personal Reflections on Security

04:14 Introduction to Stacklok and Minder

05:02 Minder's Features and Capabilities

07:38 Target Audience and Use Cases for Minder

10:41 Balancing Security and Developer Productivity

13:00 The Importance of Seamless Security

13:52 Introduction to Trusty: Understanding Open Source Security Risks

14:45 Analyzing Malicious Packages and Developer Contributions

18:06 The Role of Developer Identity in Open Source Projects

19:20 AI's Impact on Code Development and Security

20:10 Challenges and Future Directions in Developer Identity

23:31 Concluding Thoughts and Future Conversations

Guest:

Luke Hinds is the CTO of Stacklok. He is the creator of the open source project sigstore, which makes it easier for developers to sign and verify software artifacts. Prior to Stacklok, Luke was a distinguished engineer at Red Hat.

  continue reading

100 episodes

Artwork
iconShare
 
Manage episode 472469494 series 3446189
Content provided by open.intel. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by open.intel or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

In this episode, we sit down with Luke Hinds, CTO of Stacklok and creator of Sigstore, to learn from his extensive background in open source security. Luke shares insights into his journey and passion for security, highlighting the thrill of the 'cat and mouse' dynamics. He discusses Stacklok’s project, Minder, a software supply chain platform designed to streamline security while boosting developer productivity. Luke also touches on Trusty, another Stacklok initiative aimed at assessing the security risks of open source packages using data science. The conversation expands to the impact of AI on code contributions and developer identity, reflecting on the evolving dynamics in software development and security. Finally, Luke shares thoughts on the ongoing challenges and opportunities in bridging the gap between operations and engineering to maintain robust security in fast-paced development environments.

00:00 Introduction

02:29 Personal Reflections on Security

04:14 Introduction to Stacklok and Minder

05:02 Minder's Features and Capabilities

07:38 Target Audience and Use Cases for Minder

10:41 Balancing Security and Developer Productivity

13:00 The Importance of Seamless Security

13:52 Introduction to Trusty: Understanding Open Source Security Risks

14:45 Analyzing Malicious Packages and Developer Contributions

18:06 The Role of Developer Identity in Open Source Projects

19:20 AI's Impact on Code Development and Security

20:10 Challenges and Future Directions in Developer Identity

23:31 Concluding Thoughts and Future Conversations

Guest:

Luke Hinds is the CTO of Stacklok. He is the creator of the open source project sigstore, which makes it easier for developers to sign and verify software artifacts. Prior to Stacklok, Luke was a distinguished engineer at Red Hat.

  continue reading

100 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

icon Daily Deals
icon Daily Deals
icon Daily Deals

Quick Reference Guide

Listen to this show while you explore
Play