Session
Securing Software Delivery Pipelines in the Age of AI: Introducing OWASP SPVS
Software delivery pipelines have become one of the most important and most attacked parts of the modern software ecosystem. From source control and build systems to artifact repositories, deployment workflows, and runtime operations, weaknesses in the pipeline can undermine the security of everything that follows.
In this session, Farshad Abasi and Cameron Walters will introduce the OWASP Secure Pipeline Verification Standard (SPVS), a practical framework for assessing and improving the security of software delivery pipelines across the full lifecycle. SPVS helps organizations evaluate pipeline security in a structured way across Plan, Develop, Integrate, Release, and Operate.
The talk will show why pipeline security has to be treated as more than CI/CD hardening. Modern delivery environments now include cloud-native build infrastructure, deployment automation, software supply chain dependencies, and increasingly, AI-assisted and agentic tooling that can influence how software is written, reviewed, built, and shipped. SPVS gives teams a practical model for evaluating governance, trust boundaries, permissions, verification, and operational controls across that entire system.
Attendees will leave with a clear understanding of where SPVS fits in a modern AppSec and DevSecOps program, why pipeline security deserves to be treated as a first-class discipline, and how to use SPVS as a roadmap for improving delivery security maturity in real-world environments.
Farshad Abasi
Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author
Vancouver, Canada
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top