Services

Open source

EN

KUBICAST #183 - Secure Development in Go

Secure development goes beyond plugins in SonarQube.

mansplainer

João Brito

Security in Go is not just about "running a scanner and praying." In this episode, we break down how to write Go with an attacker's mindset: dependency governance (and the dangers of type-squatting), reviewing go.mod, judicious use of the Standard Library, and why you should not use latest in images. We also connect technology with process: private repositories, approval policies, and pipelines that block regressions before deployment.

The conversation stems from real cases: from the typo in (GHCR vs GHRC) that captures credentials to the confusion with fake packages like BoltDB look-alikes. We discuss end-to-end supply chain, Go Proxy cache, licenses (when to avoid GPL), and best practices for authentication.

And of course, we go beyond the code: SBOM in builds, image signing and verification, OPA/Admission Control for Kubernetes policies, minimum capabilities, and input validation with well-defined timeouts. It's practical talk, with our usual humor, to make security the default — not a last-minute chore.



Important Links:

- Marcelo Pires - https://www.linkedin.com/in/marcpires/

- Matheus Faria - https://www.linkedin.com/in/matheusfm/

- João Brito - https://www.linkedin.com/in/juniorjbn

- Watch the Movie TEArapia - https://youtu.be/M4QFmW_HZh0?si=HIXBDWZJ8yPbpflM -

Post about ghrc.io - https://www.linkedin.com/posts/juniorjbn_someone-is-typosquatting-ghrcio-not-github-activity-7364387040618045441-UB88/

- Typosquat - https://devops.com/typosquat-supply-chain-attack-targets-go-developers/

- https://go.dev/doc/tutorial/govulncheck

- vuln.go.dev

- https://github.com/anchore/syft

- https://github.com/anchore/grype

- https://github.com/google/capslock

- https://github.com/aquasecurity/trivy

- LFD121 - https://training.linuxfoundation.org/training/developing-secure-software-lfd121/

- https://deps.dev/

- https://devops.com/typosquat-supply-chain-attack-targets-go-developers/


Join our early access program and have a more secure environment in moments! https://getup.io/zerocve

🎧 Also listen to Kubicast on Spotify, and share it with everyone in development who needs to know a bit more about the topic!

Newsletter Getup.

Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.

Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.