Rob Bos

Information & Communications Technology

Azure Azure DevOps Visual Studio / .NET .net core Entity Framework GitHub GitHub Actions GitHub Advanced Security

's-Hertogenbosch, North Brabant, Netherlands

Protect yourself against supply chain attacks

As an industry, we are using third party packages and building components for lots of things. In this supply chain, there are lots of places for vulnerabilities. They can then be used to attack your DevOps pipelines!

In this session, I will go over some common attack examples and show you a way to prevent them from happening. There are frameworks available in the industry that guide you through the process of becoming more mature in protecting not only your source code and application but also the packages you use and the pipelines you build them with. I'll demo some of GitHub's features that help preventing these types of attacks

Given at NDC Security in Oslo - April 2022


Rob Bos

DevOps Consultant @ Xpirit

Rob has a strong focus on ALM and DevOps, automating manual tasks and helping teams deliver value to the end-user faster, using DevOps techniques. This is applied on anything Rob comes across, whether it’s an application, infrastructure, serverless or training environments. Additionally, Rob focuses on the management of production environments, including dashboarding, usage statistics for product owners and stakeholders, but also as part of the feedback loop to the developers. A lot of focus goes to GitHub and GitHub Actions, improving the security of applications and DevOps pipelines.

Rob's full speaker profile