WeAreDevelopers LIVE Aug 5, 2026

WeAreDevelopers LIVE - Node and Package Security

Chris Heilmann , Daniel Cranney , Zbyszek Tenerowicz

Are malicious post-install scripts threatening your JavaScript projects? Stop attackers in their tracks. Learn how to neutralize supply chain vulnerabilities using LavaMoat Harden and strict node permissions.

Pause
Mute Enter Fullscreen
#1 about 4 min

Defining the product marketing manager role in tech

How product marketing aligns external audience perception with internal company goals.

#2 about 7 min

Viability of open-source mobile operating systems

The challenges of building alternatives to mainstream mobile platforms and adapting to modular hardware.

#3 about 9 min

Regulating deepfake content and AI transparency in Europe

How the European Union enforces labels on AI-generated content to protect digital identities.

#4 about 7 min

Balancing AI automation with human curation in content creation

Strategies for utilizing AI to draft content while maintaining quality and authentic human intent.

#5 about 7 min

Eliminating cookie banners through browser-level privacy settings

How European regulations aim to replace disruptive cookie banners with standardized browser consent.

#6 about 2 min

Preventing web scraping using ligature-based typography tricks

The accessibility trade-offs of hiding text from AI scrapers using visual font overlays.

#7 about 5 min

Exploring community-built data analysis tools and visualizations

A look at creative side projects like Wikipedia image searchers and the IKEA complexity index.

#8 about 7 min

Measuring password vulnerability against future quantum computing threats

How cryptographic researchers compete to optimize algorithms for quantum-based password cracking.

#9 about 2 min

Reverting destructive Unix commands with the Undo utility

How the Undo tool leverages shell hooks to recover from accidental command-line deletions.

#10 about 6 min

Testing technology knowledge with a tech news trivia game

A trivia segment challenging guests to identify real versus fabricated software and technology headlines.

#11 about 5 min

Securing package managers using the Lavamoat Harden project

Automating package manager configuration to mitigate supply chain attacks and malicious installation scripts.

#12 about 4 min

Automating staged publishing for secure package releases

Using custom bookmarklets to streamline two-factor authentication and staged publishing workflows on npm.

#13 about 10 min

Limiting script execution permissions in Node and package managers

Restricting disk and network access for package scripts to prevent unauthorized data exfiltration.

Matching moments

14:53 min

Audience questions on tool configurations and package locks

Zbyszek Tenerowicz · LIVE

5:34 min

Addressing audience concerns on licensing and privacy

Thomas Dohmke Thomas Dohmke · World Congress 2022

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · World Congress 2024

9:35 min

Audience questions on model security and continuous fuzzing

Natalie Pistunovich · LIVE

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 4

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

How Docker caught a supply chain attack in 83 minutes

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma