
How To Secure Open-Source Dependencies - BONUS
12/16/22 • 43 min
Stephen Chin is the Head of Developer Relations at JFROG. He is also a Speaker and the Author of DevOps Tools for Java Developers. Stephen joins Chuck for this bonus episode to talk about Supply Chain Security and Pyrsia.io. He begins by sharing some instances of how attackers are able to access different companies’ assets, software, systems, and others.
Additionally, Stephen offers solutions on how to prevent or eliminate those attacks. Pyrsia.io is a solution that secures open-source builds and distribution with the goal of securing the software supply chain of open-source dependencies.
Links
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
Stephen Chin is the Head of Developer Relations at JFROG. He is also a Speaker and the Author of DevOps Tools for Java Developers. Stephen joins Chuck for this bonus episode to talk about Supply Chain Security and Pyrsia.io. He begins by sharing some instances of how attackers are able to access different companies’ assets, software, systems, and others.
Additionally, Stephen offers solutions on how to prevent or eliminate those attacks. Pyrsia.io is a solution that secures open-source builds and distribution with the goal of securing the software supply chain of open-source dependencies.
Links
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
Previous Episode

SwampUp: Process for Fixing System Issues & Delivering Integrations Efficiently - DevOps 141
Join Chuck Wood as he hosts the DevOps episode this week to do an interview with one of the SwampUp speakers. SwampUp is an in-person DevOps event organized by JFrog. Fernando Babadopulos is an Eternal software developer, serial entrepreneur, and speaker. He is also the Co-Founder at the tail.digital. He talks about a plugin that they developed, how it works and how developers can benefit from it.
About this Episode
- All about JFrog's X-ray Integration
- How the plugin resolves system issues
- Process of creating a plugin
For the second part of this episode, Chuck Wood interviews other SwampUp speakers. Eli Aleyner and Sergei Egorov are both the Co-founders of AtomicJar. The goal of AtomicJar is to create developer-friendly tools that will improve automated testing.
About This Episode
- The basics of Integration Testing
- All about Test Containers
- Test containers' benefit to developers
Sponsors
- Chuck's Resume Template
- Developer Book Club starting with Clean Architecture by Robert C. Martin
- Become a Top 1% Dev with a Top End Devs Membership
Links
- jfrog/frogbot
- swampUP 2022 DevOps City Tour
- Twitter: @jfrog
- Twitter: @babadopulos
- AtomicJar
- Testcontainers
- Testcontainers cloud
- Testcontainers for Java
- Twitter: @ealeyner
- Twitter: @bsideup
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
Next Episode

Learning How To Learn - DevOps 142
As a developer, you should “Focus on solving business problems rather than technical expertise”. The panel joins the show to talk about Will’s YouTube video, “Don’t Do DevOps”. They offer their advice on how to advance with your career and expertise when a certain tool, framework, or language you’re focused on is suddenly not your company’s focus. As new developers grow in their careers, they also share tips on how to specialize in a particular area and learn the "basics" especially when you're starting your career.
Sponsors
- Chuck's Resume Template
- Developer Book Club starting with Clean Architecture by Robert C. Martin
- Become a Top 1% Dev with a Top End Devs Membership
Links
Picks
- Jillian - Watch The Dragon Prince | Netflix Official Site
- Jonathan - Fix This Next
- Jonathan - Hire Jonathan
- Will - Die Hard (1988) - IMDb
- Will - Leadership Strategy and Tactics
- Will - The Metaverse Podcast on Apple Podcasts
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
If you like this episode you’ll love
Episode Comments
Generate a badge
Get a badge for your website that links back to this episode
<a href="https://goodpods.com/podcasts/adventures-in-devops-351147/how-to-secure-open-source-dependencies-bonus-50812286"> <img src="https://storage.googleapis.com/goodpods-images-bucket/badges/generic-badge-1.svg" alt="listen to how to secure open-source dependencies - bonus on goodpods" style="width: 225px" /> </a>
Copy