Going beyond compliance with cybersecurity experts and open-source professionals.
21 min
Open source contributes a significant part of the applications that our teams build everyday. Unfortunately, criminals have found that attacking the supply chains underpinning these open source projects is a very effective way to gain access to many targets at once. We saw this recently with the xz-utils/liblzma software supply chain attack. Customers are waking up to the fact that the bad guys have the ability, and are inclined to spend years building sophisticated attacks on the open source software we all depend on. In this talk Paul will describe a real-world software supply chain issue he ran into and how it affected the customer. Luckily this wasn't an attack, but it had significant consequences for the customer consuming open source. This presentation will also describe a number of tools and processes for identifying risk in open source software supply chains.

Red Team Staff Engineer at GitLab
We use tools on this site to collect and record your data (e.g., your searches), which we and our vendors may use to provide, improve, and personalize our offerings, make recommendations, and for analytics and marketing. Some of these tools identify visitors and link website activity to business contact and company information so we can better understand interest in our services and tailor our outreach. We may share your data with third parties, such as advertising vendors, social media companies, and research partners, which may be "targeted advertising," "selling," or "sharing" under applicable privacy laws. Continuing to browse our site means you accept these terms and our Privacy Policy. To opt out, click the Your Privacy Choices link in the footer.