World Congress 2025 • Aug 20, 2025 • Session details

Supply Chain Security and the Real World: Lessons From Incidents

Adrian Mouat

When hackers breached Codecov, they weaponized dependencies to pivot across organizations. Learn concrete strategies to harden your CI/CD pipelines against real-world supply chain attacks.

Pause
Mute Enter Fullscreen
#1 about 2 min

The problem with abstract security metaphors

Skirting technical details in favor of imagery hinders the deployment of actionable defense patterns.

#2 about 4 min

Flaws in vague supply chain security advice

Replacing vague concepts like mapping infrastructure with concrete code implementations ensures stronger threat prevention.

#3 about 4 min

Analyzing the Codecov bash uploader script breach

Leaked storage secrets inside public containers allow attackers to alter continuous integration automation scripts.

#4 about 2 min

Securing build time credentials in Docker containers

Suppressing files within sequential Docker layers fails to effectively purge sensitive build credentials.

#5 about 4 min

Validating installation scripts and external downloads safely

Verifying direct bash downloads with robust checksums or signatures prevents execution of corrupted binaries.

#6 about 2 min

Risks of storing credentials in environment variables

Embedding configurations within environment formats unnecessarily risks widespread credential exposure across entire execution environments.

#7 about 5 min

Compromised dependencies in GitHub Action workflows

Indirect dependencies compromising review workflows demonstrate the collateral surface area of targeted pipeline attacks.

#8 about 2 min

Mitigating repository vulnerabilities through contributor verification

Enforcing rigorous commit signing and tag restrictions protects core repositories from unauthorized behavioral shifts.

#9 about 2 min

Pinning automation processes to cryptographic digests

Binding automation steps to explicit cryptographic digests ensures environments execute immutable container configurations.

#10 about 3 min

Eliminating long-lived credentials to reduce exposure patterns

Replacing long-lived authentication keys with temporary workflow identities significantly narrows unauthorized access windows.

Matching moments

3:36 min

Understanding software supply chain threats and security risks

Andrei Epure Andrei Epure · World Congress 2024

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

3:10 min

Implementing preventative cybersecurity to mitigate software supply chain risks

Coffee With Developers

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:16 min

Avoiding supply chain risks within standard software dependencies

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

1:37 min

Introduction to supply chain security principles

Zbyszek Tenerowicz · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

How Docker caught a supply chain attack in 83 minutes

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer, Dokcer

Mark Lechner