Session

Getting Started with SLSA, SBOMs, and Attestation Without Breaking the Build

With impending regulatory standards like the EU Cyber Resilience Act (CRA) and the rise of automated, agentic code generation, securing software supply chains is no longer optional—it is an operational mandate. However, for most engineering teams maintaining mission-critical libraries and pipelines, implementing SLSA frameworks, generating meaningful SBOMs, and establishing cryptographic attestations can quickly become a bottleneck that grinds developer velocity to a halt.

Drawing from hands-on work modernizing CI/CD pipelines across foundational open-source ecosystems (including go-yaml and pyyaml), this session provides a practical, zero-fluff walkthrough of implementing supply chain security without breaking existing build workflows.

Key Takeaways:

Demystifying the Acronyms: Cutting through the noise of SLSA levels, in-toto attestations, and SBOM standards (SPDX vs. CycloneDX).

Pragmatic CI/CD Integration: How to automate artifact signing and provenance generation in GitHub Actions with minimal build friction.

CRA & Regulatory Readiness: Understanding what EU compliance realistically requires from maintainers and enterprise engineering teams.

The Agentic CI/CD Era: Ensuring pipeline integrity when AI agents contribute directly to the commit graph.


Presented for Cloud Native Foundation Seattle

Format: Standard Presentation / Tech Talk (30–45 min)

Track: DevSecOps / Cloud Native Infrastructure / Supply Chain Security

Aaron Bronow

Building robust software, resilient teams, and zero-nonsense architecture.

Seattle, Washington, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top