Session

Preparing Your GitHub Supply Chain for the EU Cyber Resilience Act (CRA)

The EU Cyber Resilience Act (CRA) is reshaping how software is built, distributed, and maintained globally. If your product ships software components to European users or relies on open-source dependencies, your engineering organization must adapt its development lifecycle to meet stringent provenance, vulnerability management, and reporting requirements.

This hands-on workshop walks engineering leaders, founders, and DevSecOps practitioners through auditing and hardening their GitHub supply chain for compliance. We will move beyond abstract policies to examine actual repository configurations, automated dependency vetting, and compliance-ready pipeline architecture that protects your product without suffocating developer momentum.

Key Takeaways:

Deconstructing CRA Requirements: What software makers and maintainers actually need to document and verify.

Hardening GitHub Workflows: Enforcing branch protections, secret hygiene, and provenance attestation at the repository level.

Automated Dependency Governance: Strategies for scanning, tracking, and remediating upstream supply chain risks in real time.

Actionable Compliance Blueprint: A concrete checklist you can take directly back to your team to assess compliance readiness.


Prepared for LA Tech Week October 2026

Format: Interactive Workshop / Deep-Dive Session (45–60 min)

Track: Engineering Leadership / DevSecOps / Product Compliance

Aaron Bronow

Building robust software, resilient teams, and zero-nonsense architecture.

Seattle, Washington, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top