SLSA, SBOMs and Attestation | Aaron Bronow, The YAML Company | Cloud Native Seattle - September
Cloud Native Seattle
0:00 / 0:00
SLSA, SBOMs and Attestation | Aaron Bronow, The YAML Company | Cloud Native Seattle - September
9 просмотров · 9 дней назад
Cloud Native Seattle
4 подписчика
9 просмотров · 9 дней назад
Security frameworks like SLSA and regulations demanding comprehensive SBOMs are no longer optional—but implementing them often feels like throwing a wrench into a smoothly running CI/CD pipeline. Compliance shouldn't mean sacrificing developer velocity.
In this talk, we’ll cut through the buzzwords and lay out a practical roadmap for integrating artifact attestation and provenance tracking into your existing build systems seamlessly. You will leave with a clear understanding of how to establish cryptographic trust, generate verifiable SBOMs automatically, and satisfy strict compliance requirements—all without waking up your on-call engineer or breaking a single build.
SLIDES = https://tinyurl.com/cncf-sea-05-slide...
About Speaker:
Aaron Bronow is a co-founder of The YAML Company and a software engineering leader with prior leadership roles at Expedia and Good World Solutions. He focuses on building open-source tools that solve software supply chain security challenges without breaking developer velocity. Based in Seattle, Aaron is a cyclist, dog dad, and taking guitar lessons.
About the Event:
This talk was presented at Cloud Native Seattle - the official CNCF Community Group in Seattle Area. This event was hosted at Pure Storage in City Center, Bellevue on September 16th 2026.
A big thank you to Pure Storage for sponsoring venue, food and drinks for the event.