> Markdown version of [/events/world-congress-2025/sessions/685-supply-chain](https://www.wearedevelopers.com/events/world-congress-2025/sessions/685-supply-chain). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Supply Chain Security and the Real World: Lessons From Incidents - **Date:** Thursday, Jul 10, 2025 - **Time:** 16:50–17:20 (30 min) - **Room:** Stage 8 - **Event:** World Congress 2025 - **Tags:** cybersecurity ## Recording [Watch recording](https://www.wearedevelopers.com/videos/1656-supply-chain-security-and-the-real-world-lessons-from-incidents) ## Description Supply chain security is becoming more and more important, but it is often talked about in abstract and general terms that do little to help the average organisation. Sophisticated and not-so sophisticated breaches and attacks in recent years have taught us a lot about the soft spots that attackers target. We can these insights into actionable advice for the average devops team. This talk will look at some real world examples of supply chain compromises and translate the lessons into concrete actions that you can take today to help secure your builds and pipelines. The incidents we’ll look at include the codecov breach and the recent changed-files attack. I’ll show how straightforward changes to build processes and CI/CD settings can help prevent similar attacks and mitigate the effects when dependencies are breached. Supply chain security is becoming more and more important, but it is often talked about in abstract and general terms that do little to help the average organisation. Sophisticated and not-so sophisticated breaches and attacks in recent years have taught us a lot about the soft spots that attackers target. We can these insights into actionable advice for the average devops team. This talk will look at some real world examples of supply chain compromises and translate the lessons into concrete actions that you can take today to help secure your builds and pipelines. The incidents we’ll look at include the codecov breach and the recent changed-files attack. I’ll show how straightforward changes to build processes and CI/CD settings can help prevent similar attacks and mitigate the effects when dependencies are breached. ## Speaker ### [Adrian Mouat](https://www.wearedevelopers.com/@adrian-mouat) Technical Community Advocate at Chainguard ## Related talks at this congress - [Better Safe Than Sorry: Preparing for the Next Supply Chain Attack with SBOMs](https://www.wearedevelopers.com/events/world-congress-2025/sessions/876-better-safe-than) — Julia Gätjens - [Code Red: When Your Tools Turn Against You ](https://www.wearedevelopers.com/events/world-congress-2025/sessions/510-code-red-when-your) — Aaron Bray, Julian Totzek-Hallhuber - [How GitHub secures open source](https://www.wearedevelopers.com/events/world-congress-2025/sessions/670-how-github-secures) — Joseph Katsioloudes - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/events/world-congress-2025/sessions/844-why-security-first) — Michael Wildpaner