Talk
Beginner
Apache 2.0
Your Package Manager Is not your friend: Install-Time Attacks and How to Stop Them
Review Pending
Sudhanshu Dasgupta
Session Categories
Technology architecture
Introducing a FOSS project or a new version of a popular project
Talk License:
Apache 2.0
Which track are you applying for?
Security
Speakers
Sudhanshu Dasgupta
Software Engineer | SafeDep
Sudhanshu Dasgupta is a Software Engineer at SafeDep, where he works on building infrastructure for open source supply chain security and contributes to tools that help developers detect and block malicious packages before they reach production. He is also actively involved in educating developers on emerging supply chain threats and raising awareness around secure dependency practices.
He is also a core maintainer of Meshery, an open-source CNCF sandbox project for cloud-native infrastructure management. You will find him talking on open-source, supply chain security, cloud-native technologies, and community building. He actively mentor and guide new contributors, helping them navigate and grow in the open-source ecosystem.
Reviews
No reviews yet.