What I Got Wrong Shipping an MCP Server for Live Infrastructure
-
Pritesh Kiri
Harness
Developer Relations Engineer
November 25–26, 2026
Bengaluru, India
Joining remotely?
Watch live with ProOn March 31, the Axios npm package was compromised for about 3 hours. Two bad versions shipped with a hidden dependency that pulled a remote access trojan onto Linux, macOS, and Windows. Axios does over 70 million downloads a week. If your CI ran an unpinned install in that window, you found out fast what your incident response looks like.
Three weeks later another npm worm started spreading through stolen publish tokens. Then a PyPI package. Then the Docker images for Checkmarx KICS.
Most engineers can’t quickly answer the one question that matters when this happens: are we exposed, and where? This talk covers the basics most of us never got. What’s an SBOM and why should you care? How to read a CVE. What a VEX statement actually does, and how it can save your team a weekend of arguing about whether a CVE even applies.
Then what I actually do. In dev, I catch bad dependencies before they get committed. In CI, I keep the pipeline itself honest. In production, I run on hardened, signed base images. That’s where Docker Hardened Images fit in, and I’ll share what changed after I switched.
I’ll cover the tools I kept, the ones I dropped, and a few things I got wrong the first time.
Conference India 2026
Pritesh Kiri
Harness
Developer Relations Engineer
Hadar Geva
Myop
CTO & Co-founder
Vikram Vaswani
Consultant
Deepak Agrawal
Atlassian
Principal Software Engineer