Skip to Main Content
Talk Intermediate

Shifting Left for Real: OpenSSF Tools for the Modern DevOps Pipeline

Approved
Session Description

Modern DevOps has a paradox at its core: we build our most secure enterprise systems on top of thousands of open-source pieces we don't own, didn't write, and rarely audit. Incidents like the XZ Utils backdoor and Log4Shell made one thing terrifyingly clear,the open-source software (OSS) supply chain is the primary target for modern attackers.

But if open source is where the vulnerabilities are, why is open-source tooling our best defense?

In this talk, we will explore why proprietary, black-box security tools are failing to protect open-source ecosystems. We will introduce the Open Source Security Foundation (OpenSSF), a cross-industry initiative dedicated to fixing OSS security from the inside out.

We’ll look past the theoretical governance and dive into how OpenSSF creates open, standardized, community-driven tools that integrate directly into your DevOps pipelines. We will walk through three core pillars of the OpenSSF toolset:

  1. OpenSSF Scorecards: Bringing radical transparency to OSS by automatically measuring the security posture of your upstream dependencies.

  2. Sigstore: Cryptographic signing made so easy that we can finally eliminate static PGP keys and establish decentralized trust.

  3. SLSA (Supply chain Levels for Software Artifacts): An open framework for building tamper-resistant pipelines so you can prove exactly where your code came from.

Come learn why the future of security must be open-source, and how you can use OpenSSF tools to start verifying—not just trusting—your software stack.

Key Takeaways
  • The DevOps Security Reality Check: Why traditional vulnerability scanners miss supply chain attacks, and why artifact integrity matters.

  • Automated Dependency Auditing: How to integrate OpenSSF Scorecard into your CI/CD to block risky or unmaintained dependencies automatically.

  • Keyless Artifact Signing: A live look (or walkthrough) at using Sigstore/Cosign to sign container images using OIDC providers (like GitHub Actions, GitLab CI, or cloud IAM) instead of managing static keys.

  • The Tamper-Proof Pipeline: Practical steps to align your current infrastructure with the SLSA framework to protect your build servers.

References

Session Categories

Other

Speakers

Ashok M Technical Account Manager | DigitalOcean

Golden Kubestronaut, 2xAWS Certified Cloud and AI Practitioner. Technical Account Manager at DigitalOcean. I have security related Experience in CNAPP products. CSPM,CWPP,ASPM,KSPM ,SIEM and other observability solutions.

Ashok M
https://www.linkedin.com/in/ashok-m-%E0%AE%85%E0%AE%9A%E0%AF%8B%E0%AE%95%E0%AF%8D-%E0%AE%AE%E0%AF%82-bb5229154/