WeAreDevelopers LIVE Aug 5, 2026

WeAreDevelopers LIVE - Node and Package Security

Chris Heilmann , Daniel Cranney , Zbyszek Tenerowicz

Are malicious post-install scripts threatening your JavaScript projects? Stop attackers in their tracks. Learn how to neutralize supply chain vulnerabilities using LavaMoat Harden and strict node permissions.

Pause
Mute Enter Fullscreen
#1 about 4 min

Defining the product marketing manager role in tech

How product marketing aligns external audience perception with internal company goals.

#2 about 7 min

Viability of open-source mobile operating systems

The challenges of building alternatives to mainstream mobile platforms and adapting to modular hardware.

#3 about 9 min

Regulating deepfake content and AI transparency in Europe

How the European Union enforces labels on AI-generated content to protect digital identities.

#4 about 7 min

Balancing AI automation with human curation in content creation

Strategies for utilizing AI to draft content while maintaining quality and authentic human intent.

#5 about 7 min

Eliminating cookie banners through browser-level privacy settings

How European regulations aim to replace disruptive cookie banners with standardized browser consent.

#6 about 2 min

Preventing web scraping using ligature-based typography tricks

The accessibility trade-offs of hiding text from AI scrapers using visual font overlays.

#7 about 5 min

Exploring community-built data analysis tools and visualizations

A look at creative side projects like Wikipedia image searchers and the IKEA complexity index.

#8 about 7 min

Measuring password vulnerability against future quantum computing threats

How cryptographic researchers compete to optimize algorithms for quantum-based password cracking.

#9 about 2 min

Reverting destructive Unix commands with the Undo utility

How the Undo tool leverages shell hooks to recover from accidental command-line deletions.

#10 about 6 min

Testing technology knowledge with a tech news trivia game

A trivia segment challenging guests to identify real versus fabricated software and technology headlines.

#11 about 5 min

Securing package managers using the Lavamoat Harden project

Automating package manager configuration to mitigate supply chain attacks and malicious installation scripts.

#12 about 4 min

Automating staged publishing for secure package releases

Using custom bookmarklets to streamline two-factor authentication and staged publishing workflows on npm.

#13 about 10 min

Limiting script execution permissions in Node and package managers

Restricting disk and network access for package scripts to prevent unauthorized data exfiltration.

Matching moments

14:53 min

Audience questions on tool configurations and package locks

Zbyszek Tenerowicz · LIVE

5:34 min

Addressing audience concerns on licensing and privacy

Thomas Dohmke Thomas Dohmke · WWC 2022

2:30 min

Bridging the gap between developers and security tools

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · WWC 2024

9:35 min

Audience questions on model security and continuous fuzzing

Natalie Pistunovich · LIVE

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann +2 · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane