Table of Contents
Prefaceix
1
Introduction to the Security Landscape1
The evolving application security landscape
Security awareness
Regulatory compliance and legal considerations
Who are the threat actors?
Supply chain attack case: SolarWinds
Where GitGuardian stands in the landscape
Summary
2
The Software Supply Chain and the SDLC9
What is the software supply chain?
What is the software development life cycle?
The intersection of SDLC and SSC
SDLC stages and SSC considerations
Trustworthiness in the software supply chain
Common supply chain attack vectors and defenses
Compromise of third-party components
Supply chain poisoning via updates
Insufficient security practices in development and operations
Code repository tampering
Threat modeling ...
Get Crafting Secure Software now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.