Conference India 2026

Supply Chain Security for the Everyday Engineer

Conference India 2026

November 25–26, 2026

Bengaluru, India

Get tickets

Joining remotely?

Watch live with Pro

What this session covers

On March 31, the Axios npm package was compromised for about 3 hours. Two bad versions shipped with a hidden dependency that pulled a remote access trojan onto Linux, macOS, and Windows. Axios does over 70 million downloads a week. If your CI ran an unpinned install in that window, you found out fast what your incident response looks like.

Three weeks later another npm worm started spreading through stolen publish tokens. Then a PyPI package. Then the Docker images for Checkmarx KICS.

Most engineers can’t quickly answer the one question that matters when this happens: are we exposed, and where? This talk covers the basics most of us never got. What’s an SBOM and why should you care? How to read a CVE. What a VEX statement actually does, and how it can save your team a weekend of arguing about whether a CVE even applies.

Then what I actually do. In dev, I catch bad dependencies before they get committed. In CI, I keep the pipeline itself honest. In production, I run on hardened, signed base images. That’s where Docker Hardened Images fit in, and I’ll share what changed after I switched.

I’ll cover the tools I kept, the ones I dropped, and a few things I got wrong the first time.

Conference India 2026

Related talks

Open session

What I Got Wrong Shipping an MCP Server for Live Infrastructure

  • Pritesh Kiri

    Harness

    Developer Relations Engineer

Open session

Shipping MCP to Real Users: Scaling, Auth, and the PII Leak You Didn't See Coming

  • Hadar Geva

    Myop

    CTO & Co-founder

Open session

Beware of Strangers Bearing Code: Open Source Trust in the Agent Era

  • Vikram Vaswani

    Consultant

Open session

How We Cut Our API's p99 Latency from Minutes to Under a Second

  • Deepak Agrawal

    Atlassian

    Principal Software Engineer

All sessions at this congress