How to stop the 'Gradle Snatchers': Securing your builds from baddies

ED HOLLOWAY-GEORGE
Lead Android Developer| Android GDE
ASOS

How to stop the 'Gradle Snatchers': Securing your builds from baddies

ED HOLLOWAY-GEORGE ...
Lead Android Develop ...
ASOS

How to stop the 'Gradle Snatchers': Securing your builds from baddies

ED HOLLOWAY-GEOR ...
Lead Android Developer| A ...
ASOS

Video Infos
Author
Published
Topics
Author
Published
Following on from one of the first recorded supply chain attacks against Gradle, this talk will discuss the security concerns surrounding our favourite build tool and how we can protect against them. This starts with gaining an understanding of some of Gradle's common vulnerabilities and how to avoid these within our projects. You'll leave this talk with: - Insights on the Gradle Wrapper supply-chain attack and how to protect against it. - An overview of a Gradle dependency attack and how to protect against them. - A concrete list of security setting best practices within Gradle, including wrapper verification, repository filtering, dependency verification and others.

LATEST ANDROID JOBS

update your work life

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.

Menu