World Congress 2022 Jun 15, 2022

Securing your application software supply-chain

Niels Tanis

Are you blindly trusting your transitive dependencies? Learn how to systematically lock down your CI/CD pipeline with automated SBOMs and keyless signing before the next SolarWinds-style breach.

Pause
Mute Enter Fullscreen
#1 about 4 min

Defining the modern application software supply chain

Transitioning to cloud-native architectures introduces complex development phases that resemble industrial manufacturing processes.

#2 about 2 min

Analyzing the SolarWinds supply chain attack

Attackers compromising build servers to inject malicious code demonstrate the systemic risk of targeted digital infrastructure.

#3 about 2 min

Protecting source code repositories and developer credentials

Implementing multi-factor authentication and git commit signing prevents attackers from pushing unauthorized code via stolen credentials.

#4 about 2 min

Identifying security risks in developer IDE environments

Massive transitive dependency trees in editors create attack vectors like command injection that can arbitrarily alter source files.

#5 about 3 min

Managing risks in third-party software dependencies

Unpatched packages and dependency confusion attacks allow bad actors to exploit trust in external open-source libraries.

#6 about 3 min

Evaluating library intent using security scorecards

Utilizing standardized scoring tools helps engineering teams assess the security hygiene and expected capabilities of external packages.

#7 about 2 min

Generating deterministic and reproducible software builds

Ensuring that source files predictably compile into identical binaries prevents hidden modifications during the continuous integration process.

#8 about 3 min

Securing image deployments with keyless artifact signing

Associating code artifacts with verified corporate identities prevents the execution of untrusted containers in cloud environments.

#9 about 3 min

Tracking components through software bills of materials

Generating granular dependency graphs provides organizations visibility into the exact versions of code running across their infrastructure.

#10 about 4 min

Adopting the SLSA framework for supply chain maturity

Progressively implementing supply chain levels enables teams to automate verifiable provenance without manually juggling cryptographic keys.

#11 about 3 min

Enforcing security policies with verified artifact telemetry

Validating signatures and verifying reproducible pipelines at the deployment boundary blocks tampered releases from reaching production environments.

#12 about 3 min

Integrating security across the application development lifecycle

Adopting a progressive approach to threat modeling supply chains ensures that security practices scale with complex modern workflows.

Matching moments

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · World Congress 2026 Europe

1:37 min

Introduction to supply chain security principles

Zbyszek Tenerowicz · LIVE

3:36 min

Understanding software supply chain threats and security risks

Andrei Epure Andrei Epure · World Congress 2024

1:16 min

Avoiding supply chain risks within standard software dependencies

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

4:00 min

Core principles for implementing DevSecOps in teams

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 24, 2026 · 13:30–14:00

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

How Docker caught a supply chain attack in 83 minutes

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma