World Congress 2025 Aug 20, 2025 Session details

Supply Chain Security and the Real World: Lessons From Incidents

Adrian Mouat

When hackers breached Codecov, they weaponized dependencies to pivot across organizations. Learn concrete strategies to harden your CI/CD pipelines against real-world supply chain attacks.

Pause
Mute Enter Fullscreen
#1 about 2 min

The problem with abstract security metaphors

Skirting technical details in favor of imagery hinders the deployment of actionable defense patterns.

#2 about 4 min

Flaws in vague supply chain security advice

Replacing vague concepts like mapping infrastructure with concrete code implementations ensures stronger threat prevention.

#3 about 4 min

Analyzing the Codecov bash uploader script breach

Leaked storage secrets inside public containers allow attackers to alter continuous integration automation scripts.

#4 about 2 min

Securing build time credentials in Docker containers

Suppressing files within sequential Docker layers fails to effectively purge sensitive build credentials.

#5 about 4 min

Validating installation scripts and external downloads safely

Verifying direct bash downloads with robust checksums or signatures prevents execution of corrupted binaries.

#6 about 2 min

Risks of storing credentials in environment variables

Embedding configurations within environment formats unnecessarily risks widespread credential exposure across entire execution environments.

#7 about 5 min

Compromised dependencies in GitHub Action workflows

Indirect dependencies compromising review workflows demonstrate the collateral surface area of targeted pipeline attacks.

#8 about 2 min

Mitigating repository vulnerabilities through contributor verification

Enforcing rigorous commit signing and tag restrictions protects core repositories from unauthorized behavioral shifts.

#9 about 2 min

Pinning automation processes to cryptographic digests

Binding automation steps to explicit cryptographic digests ensures environments execute immutable container configurations.

#10 about 3 min

Eliminating long-lived credentials to reduce exposure patterns

Replacing long-lived authentication keys with temporary workflow identities significantly narrows unauthorized access windows.

Matching moments

3:36 min

Understanding software supply chain threats and security risks

Andrei Epure Andrei Epure · WWC 2024

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · WWC Europe 2026

3:10 min

Implementing preventative cybersecurity to mitigate software supply chain risks

Coffee With Developers

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · WWC Europe 2026

1:16 min

Avoiding supply chain risks within standard software dependencies

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

1:37 min

Introduction to supply chain security principles

Zbyszek Tenerowicz · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

Farshad Abasi

CEO/Founder, Eureka DevSecOps + Forward Security

Farshad Abasi
Open session

World Congress 2026 North America

Know Your Enemies: Live Exploit of a PHP Engine Security Breach

Alexandre Daubois

CTO of Les-Tilleuls.coop / Symfony Core Team / PHP & FrankenPHP Core Maintainer

Alexandre Daubois