Session
Getting Started with SLSA, SBOMs, and Attestation Without Breaking the Build
With impending regulatory standards like the EU Cyber Resilience Act (CRA) and the rise of automated, agentic code generation, securing software supply chains is no longer optional—it is an operational mandate. However, for most engineering teams maintaining mission-critical libraries and pipelines, implementing SLSA frameworks, generating meaningful SBOMs, and establishing cryptographic attestations can quickly become a bottleneck that grinds developer velocity to a halt.
Drawing from hands-on work modernizing CI/CD pipelines across foundational open-source ecosystems (including go-yaml and pyyaml), this session provides a practical, zero-fluff walkthrough of implementing supply chain security without breaking existing build workflows.
Key Takeaways:
Demystifying the Acronyms: Cutting through the noise of SLSA levels, in-toto attestations, and SBOM standards (SPDX vs. CycloneDX).
Pragmatic CI/CD Integration: How to automate artifact signing and provenance generation in GitHub Actions with minimal build friction.
CRA & Regulatory Readiness: Understanding what EU compliance realistically requires from maintainers and enterprise engineering teams.
The Agentic CI/CD Era: Ensuring pipeline integrity when AI agents contribute directly to the commit graph.
Presented for Cloud Native Foundation Seattle
Format: Standard Presentation / Tech Talk (30–45 min)
Track: DevSecOps / Cloud Native Infrastructure / Supply Chain Security
Aaron Bronow
Building robust software, resilient teams, and zero-nonsense architecture.
Seattle, Washington, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top