Talk

Beyond SBOMs: The Future of Container Supply Chain Security

When a single phished NPM maintainer led to 18 compromised libraries—including Chalk and Debug, downloaded billions of times weekly—it proved one thing: basic SBOMs alone aren't enough. But when the recent "Mini Shai Hulud" worm and its family of variants began silently tunneling through CI/CD pipelines to infect downstream containers, it proved our entire approach to build-time security needs a massive upgrade.

May 6, 2026
DevOpsDays Zurich 2026 · Zurich, Switzerland
Beyond SBOMs: The Future of Container Supply Chain Security

Delivered at DevOpsDays Zurich 2026.

Socks with colors matching the DevOpsDays Zurich theme.
Event detail

Matching Colors

A small color match with the DevOpsDays Zurich theme.

Audience view of the DevOpsDays Zurich talk slides mentioning Shai-Hulud.
Talk photo

Slides on Shai-Hulud

Audience view of the Shai-Hulud section during Beyond SBOMs at DevOpsDays Zurich 2026.

Stage view with Norse gods slide during Beyond SBOMs at DevOpsDays Zurich 2026.
Talk photo

Stage and Norse Gods

Norse gods on the slides during Beyond SBOMs at DevOpsDays Zurich 2026.

Invite Me to Speak

Available for conferences, workshops, corporate training, and meetups. I can present remotely or travel to your event.