World Congress 2022 Jun 15, 2022

Securing your application software supply-chain

Niels Tanis

Are you blindly trusting your transitive dependencies? Learn how to systematically lock down your CI/CD pipeline with automated SBOMs and keyless signing before the next SolarWinds-style breach.

Pause
Mute Enter Fullscreen
#1 about 4 min

Defining the modern application software supply chain

Transitioning to cloud-native architectures introduces complex development phases that resemble industrial manufacturing processes.

#2 about 2 min

Analyzing the SolarWinds supply chain attack

Attackers compromising build servers to inject malicious code demonstrate the systemic risk of targeted digital infrastructure.

#3 about 2 min

Protecting source code repositories and developer credentials

Implementing multi-factor authentication and git commit signing prevents attackers from pushing unauthorized code via stolen credentials.

#4 about 2 min

Identifying security risks in developer IDE environments

Massive transitive dependency trees in editors create attack vectors like command injection that can arbitrarily alter source files.

#5 about 3 min

Managing risks in third-party software dependencies

Unpatched packages and dependency confusion attacks allow bad actors to exploit trust in external open-source libraries.

#6 about 3 min

Evaluating library intent using security scorecards

Utilizing standardized scoring tools helps engineering teams assess the security hygiene and expected capabilities of external packages.

#7 about 2 min

Generating deterministic and reproducible software builds

Ensuring that source files predictably compile into identical binaries prevents hidden modifications during the continuous integration process.

#8 about 3 min

Securing image deployments with keyless artifact signing

Associating code artifacts with verified corporate identities prevents the execution of untrusted containers in cloud environments.

#9 about 3 min

Tracking components through software bills of materials

Generating granular dependency graphs provides organizations visibility into the exact versions of code running across their infrastructure.

#10 about 4 min

Adopting the SLSA framework for supply chain maturity

Progressively implementing supply chain levels enables teams to automate verifiable provenance without manually juggling cryptographic keys.

#11 about 3 min

Enforcing security policies with verified artifact telemetry

Validating signatures and verifying reproducible pipelines at the deployment boundary blocks tampered releases from reaching production environments.

#12 about 3 min

Integrating security across the application development lifecycle

Adopting a progressive approach to threat modeling supply chains ensures that security practices scale with complex modern workflows.

Matching moments

2:46 min

Mapping the complete software supply chain attack surface

Matthew Brady Matthew Brady · WWC Europe 2026

1:37 min

Introduction to supply chain security principles

Zbyszek Tenerowicz · LIVE

3:36 min

Understanding software supply chain threats and security risks

Andrei Epure Andrei Epure · WWC 2024

1:16 min

Avoiding supply chain risks within standard software dependencies

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

3:09 min

Practical mitigation strategies for modern software supply chains

Adrian Mouat Adrian Mouat · WWC Europe 2026

4:00 min

Core principles for implementing DevSecOps in teams

Aarno Aukia · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg