© Mapbox, © OpenStreetMap

Speaker

André Silva

André Silva

Software Engineer @ LexisNexis Risk Solutions - Maintainer @ OpenFeature

Dublin, Ireland

Actions

I am a passionate software developer originally from Portugal and currently based in Ireland. I specialize in building robust applications using .NET and am a dedicated advocate for open standards in feature management. As a maintainer for OpenFeature, I contribute to the project's .NET library, help shape its telemetry conventions and support efforts to standardize feature flagging across the industry.
I am committed to creating tools that simplify and enhance users’ daily lives, and I actively share my expertise through technical writing and community engagement.

Badges

Area of Expertise

  • Information & Communications Technology

Topics

  • dotNet
  • OpenSource
  • OpenFeature
  • GitHub
  • Azure
  • Microsoft Azure
  • .net dotnet

Building Secure Package Pipelines

This session guides you through creating a secure package pipeline that any open-source maintainer can achieve. I will show how we eliminated secrets with OIDC authentication, introduced automated SBOM generation for each release, signed builds with cryptographic attestations and used matrix CI to test across platforms.
We use bots to keep our dependencies up to date, CodeQL to scan our repositories for vulnerabilities and automate releases with Release Please. To increase the security of GitHub Actions, we pin hashes and permissions. These measures reduce risks associated with compromised dependencies, supply chain attacks and manual errors, while also improving compliance and trust for everyone.
By the end, you will have a blueprint for securing your projects. The ecosystem will benefit from improved security practices, increased transparency and better compliance with standards. Contributors can fork, audit and extend projects, knowing the integrity of the build process is assured.

Silent Superpowers: Why Breaking Production Isn’t Scary Anymore

Imagine unleashing new features into the wild without the fear of breaking things... Enter the world of feature flags. Picture this: your team ships code to production seamlessly, yet the power to unveil new functionalities remains entirely in your hands. This dynamic decoupling lets you test features live, roll them out gradually, and gather real-world feedback, all while mitigating risks and accelerating confident releases.

In the realm of applications, feature flag libraries weave effortlessly into your codebase, championing agile strategies like trunk-based development and dark launches. But why stop there? Step into the future with OpenFeature, an open-source, vendor-neutral standard that unifies feature flag management. With it, you wave goodbye to vendor lock-in and welcome streamlined experimentation across diverse environments.

Harnessing OpenFeature and vendor-neutral feature flags unlocks:

• Lightning-fast, risk-free deployments with hidden features until the perfect moment
• Precision targeting for canary releases, A/B tests, and tailored user experiences
• A harmonised, standardised approach to flag management across your tech ecosystem

Embrace this cutting-edge methodology to revolutionise your release process: achieve agility without sacrificing stability, and turn every deployment into an opportunity to innovate with confidence.

For this demo, I will be using Aspire and integrating it with OpenFeature to showcase the potential of these two technologies.

KCD Porto 2025 Sessionize Event

November 2025 Porto, Portugal

NDC Porto 2025 Sessionize Event

October 2025 Porto, Portugal

André Silva

Software Engineer @ LexisNexis Risk Solutions - Maintainer @ OpenFeature

Dublin, Ireland

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top