Session
Operationalizing Software Supply Chain Security at Ecosystem Scale
Modern applications are mostly code you didn't write - hundreds of transitive open-source dependencies, where a single compromised package can ripple across thousands of downstream systems. This hands-on workshop takes you from the theory of supply chain risk to the practical mechanics of defending against it at scale.
Drawing on experience running Dependabot - which monitors 30M+ repositories across 34+ package ecosystems - we walk through how dependency alerts, automated security updates, and vulnerability response work in production, and how they map to the NIST Secure Software Development Framework (SSDF). You'll triage a realistic backlog of vulnerable dependencies, prioritize remediation by severity and exploitability rather than raw CVE counts, and design an automated response workflow for your own organization - including a clear-eyed look at where AI coding agents help and where they don't.
You'll leave with a concrete, framework-aligned playbook for reducing dependency risk, not just an awareness of the problem.
Interactive workshop, co-delivered by Ankit Kumar Honey (Senior Engineering Manager, Dependabot, GitHub) and Eshaan Jain.
- Preferred duration: 90 minutes.
- Target audience: software, platform, and application-security engineers and engineering managers; intermediate level.
- Prerequisites: laptop with a code editor and Git; GitHub account helpful but not required (sample repo provided).
Ankit Kumar Honey
Engineering leader securing the world's software supply chain at GitHub (Microsoft). MS Data Science candidate at Harvard. Building AI-driven defences for 180M+ developers.
Seattle, Washington, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top