<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>John Speed Meyers on</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/contributors/john-speed-meyers/</link><description>Recent content in John Speed Meyers on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 04 Aug 2022 15:21:01 +0200</lastBuildDate><atom:link href="https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/contributors/john-speed-meyers/index.xml" rel="self" type="application/rss+xml"/><item><title>What is software supply chain security</title><link>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/software-security/what-is-software-supply-chain-security/</link><pubDate>Thu, 04 Aug 2022 15:21:01 +0200</pubDate><guid>https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/software-security/what-is-software-supply-chain-security/</guid><description>&lt;p&gt;&lt;em&gt;An earlier version of this material was published in the &lt;a href="https://learning.edx.org/course/course-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022/block-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022&amp;#43;type@sequential&amp;#43;block@1623557b9fc849d5a1e38177502b1499/block-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022&amp;#43;type@vertical&amp;#43;block@825d4b442d1346ba8e9d7c3b4f765e76"&gt;first chapter&lt;/a&gt; of the Linux Foundation &lt;a href="https://learning.edx.org/course/course-v1:LinuxFoundationX&amp;#43;LFS182x&amp;#43;2T2022/home"&gt;Sigstore course&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Software producers have a supply chain just like manufacturing businesses have a supply chain. And just like manufacturers require physical inputs and then perform a manufacturing process to build a finished product, so do software producers, whether the producer is a company or individual. In other words, a software producer uses components, developed by third parties and themselves, and technologies to write, build, and distribute software. A compromise introduced anywhere in this chain is an example of a software supply chain security issue. Tools and practices like those implemented in Chainguard&amp;rsquo;s containers help organizations protect against these risks through built-in SBOMs, provenance attestations, and SLSA compliance.&lt;/p&gt;</description></item></channel></rss>