Lightning Talk: Charting the Course for Secure Software Supply Chain with Guac-AI-Mole! - Ridwan Hoq
Автор: The Linux Foundation
Загружено: 2024-04-26
Просмотров: 197
Описание:
Lightning Talk: Charting the Course for Secure Software Supply Chain with Guac-AI-Mole! - Ridwan Hoq, Microsoft
Tracking software dependencies within an organization, particularly for open-source software, can present considerable challenges. Identifying these dependencies of running workloads in fleets of Kubernetes clusters and pinpointing those that are vulnerable can be a daunting task. This is where GUAC (Graph for Understanding Artifact Composition) comes into play. GUAC collates secure supply chain metadata, such as Software Bill of Materials (SBOMs) or Vulnerability Exploitability Exchange (VEX) statements, into a comprehensive graph database. However, learning a new query language can be challenging and time-consuming. Moreover, creating and maintaining these queries over time can prove to be a cumbersome task. Wouldn't it be more efficient if you could ask queries in natural language? For example, "Which running images have the ghsa-7rjr-3q55-vv33 vulnerability?" Using Guac-AI-mole and large language models (LLMs), it becomes possible to construct and connect queries to discover the information you need. This approach simplifies the process, making it more user-friendly and efficient.
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: