Skip to Main Content
Talk Intermediate

Trivy : Securing Your Software Supply Chain

Approved
Session Description

In today’s interconnected software ecosystem, a single vulnerable dependency can compromise your entire supply chain. Enter Trivy — a powerful, open-source scanner that’s fast becoming the developer’s go-to tool for securing everything from Docker images to SBOMs, IaC, and more.

This talk takes you on a journey through real-world patterns of how security blind spots can be discovered using Trivy. We’ll will explore how Trivy can be used as part of your CI/CD pipelines, secure infrastructure code, scan containers before they reach production, and even validate SBOMs for compliance.

You’ll walk away with a strong understanding of:

  • What Trivy scans (and what it doesn't)

  • How it fits into a DevOps pipeline

  • How to prevent supply attacks before they occur

  • Bonus: how to scale and automate scans in large orgs

If you’ve ever wondered how to make security practical, developer-friendly, and truly proactive — this talk is what you need to hear

Key Takeaways

Key Take ways :

  • Why software supply chain security is critical (with real examples)

  • How Trivy helps secure code, containers, SBOMs, and IaC

  • How to shift security left without slowing teams down

  • Tips for integrating Trivy into GitHub Actions, GitLab, and other CI/CD systems

  • Patterns for managing scan outputs, false positives, and automation

References

Session Categories

Other

Speakers

Dharan kuppusamy thamo
Architect | Bosch

As a DevOps Architect, my mastery in continuous integration and delivery has been pivotal in establishing robust deployment pipelines.

The essence of my professional journey is rooted in a steadfast commitment to process optimization and an agile mindset, harmonizing with Bosch's forward-thinking ethos. With a focus on DevOps, my role directly contributes to the organization's objective of delivering superior software solutions swiftly and accurately, reinforcing our position at the forefront of technical innovation.

https://www.linkedin.com/in/dharan-k-t-0118815/
Dharan kuppusamy thamo

Reviews

Reviewer #1 Approved

Reviewer #2 Approved

This would be useful for many people in audience to see how such tools can be put in action

Reviewer #3 Approved