Loading…
October 30, 2024
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SOSS Community Day Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard time (JST/UTC+9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
strong>Breakout Sessions [clear filter]
Wednesday, October 30
 

09:50 JST

Is This Thing on? Blue Team Tips for Scorecard - Raghav Kaul, Google
Wednesday October 30, 2024 09:50 - 10:10 JST
OpenSSF Scorecard and Allstar are tools for automatically scanning source code repositories for security misconfigurations. Scorecard looks at a GitHub or GitLab project’s source code, CI workflows, and repository settings and provides an actionable list of findings for a maintainer to improve their project’s security practices. Allstar is a way to run security analysis at scale, and automatically remediate issues. This talk will focus on one specific use case that blue teams face: how can Scorecard be used to secure first party repos? Is there a way to integrate Scorecard into an actual development process so that it doesn’t just detect an issue, but prevents it from being introduced into the supply chain? There are two aspects to this answer: infrastructure and policy. We’ll look at how probes enable the creation of granular policies, data pipelines for gathering results from probe runs, and techniques for shifting Scorecard scans left with pre-commit GitHub Actions.
Speakers
avatar for Raghav Kaul

Raghav Kaul

None, Google
Raghav is is a Security Engineer working for Google's Open Source Security Team. He is a maintainer of OpenSSF Scorecard and a contributor to OpenSSF Allstar.
Wednesday October 30, 2024 09:50 - 10:10 JST
Main Hall

10:15 JST

Future Use of SCAP and SBOM for Software Supply Chain Security - Yumi Tomita & Atsuya Misaki, Cybertrust Japan Co., Ltd. & Masaki Ishiguro, Mitsubishi Research Institute, Inc.
Wednesday October 30, 2024 10:15 - 10:35 JST
In recent years, supply chain security is strongly required as a mechanism to objectively and rationally ensure security concerning organizations, systems, products, services, and data with respect to trading partners and other stakeholders. Modern software development has become more complex due to the proliferation of multiple suppliers, vendors, and open source software (OSS), and this has increased the possibility of vulnerabilities being introduced by suppliers and the risk of attacks exploiting the supply chain in the software supply chain. This is the reason why the software supply chain is becoming more and more complex. Therefore, it is important to understand and manage security risks throughout the software supply chain. The presentation will compare SCAP, which has been used for a long time, and SBOM (Software Bill of Materials), which has been attracting attention in recent years, as a method for supply chain security, explaining the features of each, and discussing the possibilities of utilizing the tools in the future.
Speakers
avatar for Masaki Ishiguro

Masaki Ishiguro

Chief Manager and Mission Leader at Cybersecurity Strategy Group, Mitsubishi Research Institute, Inc.
Masaki Ishiguro, Ph.D., is a Chief Manager and Mission Leader at Cybersecurity Strategy Group, Mitsubishi Research Institute, Inc.His areas of expertise include Cybersecurity Technologies, Government policies, Risk Management, Cybersecurity Economics, Digital Engineering.He has completed... Read More →
avatar for Atsuya Misaki

Atsuya Misaki

Product Manager, Cybertrust Japan Co., Ltd.
Atsuya Misaki is a Product Manager in Cybertrust Japan. He works in product development related to SBOM and vulnerability management
avatar for Yumi Tomita

Yumi Tomita

Marketer, Cybertrust Japan Co., Ltd.
Yumi Tomita is a Marketer in Cybertrust Japan. She works to utilize SBOM for vulnerability management. She is a member of the OpenChain Project Japan Working Group.
Wednesday October 30, 2024 10:15 - 10:35 JST
Main Hall

11:40 JST

Continuous Security with ArgoCD and Kubescape - Anubhav Gupta, Akuity
Wednesday October 30, 2024 11:40 - 11:50 JST
In the cloud-native landscape, the integration of security into the CI/CD pipeline is not just a best practice—it's a necessity. ArgoCD has emerged as the leading GitOps controller for Kubernetes, automating deployments with precision. However, ensuring that every deployment is secure requires more than just automated workflows; it demands continuous security checks before, during, and after the deployment process. This talk will demonstrate how the combination of ArgoCD and Kubescape, a powerful open-source Kubernetes security tool, delivers a comprehensive security solution for Kubernetes deployments. We will walk through setting up an end-to-end workflow that integrates security checks into every stage of the deployment process. Attendees will learn how to implement security gates that assess vulnerabilities in container images and Kubernetes configurations before any changes are committed and receive real-time alerts if vulnerabilities are detected in production. By the end of this talk, participants will be equipped to enhance their GitOps workflows with robust security practices, making their Kubernetes deployments more resilient and secure.
Speakers
avatar for Anubhav Gupta

Anubhav Gupta

Software Engineer, Akuity
Anubhav works as a Software Engineer at Akuity. He is a graduated Summer 2023 batch LFX Mentee with the CNCF, where he worked on the Kubescape project. He is an active contributor to various CNCF projects including Kubescape and Copa. Anubhav has previously spoken at the Open Source... Read More →
Wednesday October 30, 2024 11:40 - 11:50 JST
Main Hall
 
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.