World Congress 2025
July 10, 2025 · 16:50–17:20
Stage 8
Supply Chain Security and the Real World: Lessons From Incidents
Adrian Mouat
Technical Community Advocate at Chainguard
World Congress 2025
Did you ever wonder what typosquatting, dependency confusion, malicious maintainers, or shadow libraries really mean, and how they could compromise your applications without a single line of your own code being wrong?
Welcome to the hidden war zone of modern software development: the software supply chain. In this workshop, we’ll demystify the most dangerous and fast-evolving attack vectors that are targeting developers through the tools they trust, package managers, build systems, third-party libraries, and CI/CD pipelines. Through real-world case studies and code-level examples, we’ll unpack how: Attackers exploit developer mistakes with typosquatting. Internal dependencies are hijacked via dependency confusion. Maintainers or compromised packages introduce malware into trusted ecosystems. Obscure transitive dependencies become silent backdoors.
This session is designed for developers who want to understand the risks, recognize the signs, and start building defense-in-depth strategies. If time permits, we’ll get hands-on with practical exercises where you’ll see (and maybe try) some of these attack techniques in a controlled environment—so you can learn how to defend against them in the wild. Come prepared to rethink your assumptions about open source and start building a more resilient development workflow.
World Congress 2025
July 10, 2025 · 16:50–17:20
Stage 8
Adrian Mouat
Technical Community Advocate at Chainguard
World Congress 2025
July 11, 2025 · 14:20–14:50
Stage 3 - Microsoft
Kevin Lewis
Senior Developer Advocate at GitHub
World Congress 2025
July 10, 2025 · 16:10–16:40
Stage 11
Joseph Katsioloudes
GitHub Security Lab
World Congress 2025
July 10, 2025 · 17:30–18:00
Stage 1
Liran Tal
GitHub Star | Director of Developer Advocacy at Snyk