Talks & Workshops
Talks & Workshops
Technical sessions from people who do this work — not vendor keynotes. Talks explain and demonstrate real supply-chain attacks and the defences that hold up. Workshops are hands-on.
Live demos, not slideware
Attacks and defences run in front of you, reproducible step by step — not screenshots of someone else’s terminal.
Hands-on workshops
You leave able to run the tools yourself: generate an SBOM, sign an artifact, harden a pipeline.
Vendor-neutral
Practitioners explaining how things actually work. No product pitches, no sponsor-shaped talks.
Topics we cover
The through-line is always the same: where software gets compromised on its way from source to production, and how to catch it.
SBOM generation & consumption
CycloneDX, SPDX, and what to do with a bill of materials once you have one.
Provenance & signing
SLSA, Sigstore, cosign, in-toto — proving what built an artifact and that it wasn’t tampered with.
CI/CD hardening
Build-system isolation, secret handling, and locking down the path from commit to release.
Dependency & registry attacks
Dependency confusion, typosquatting, and malicious packages on npm, PyPI, and friends.
Post-quantum & crypto-agility
What crypto agility means for the supply chain, and how to inventory what needs to change.
AI/ML supply chain
Model and dataset provenance, ML-BOM, and the new attack surface that ships with AI systems.
Archive
Sessions are published here after each edition — title, speaker, abstract, and slides or video where available.
First edition — coming soon
The inaugural line-up is being assembled. Once talks are confirmed they’ll appear here, grouped by event and year.
c0c0n 2026 · 9–10 October · Kochi
Call for Workshops
We’re looking for practitioners to run hands-on workshops at the Village. Practical problems, real tools, working code — not slide-heavy presentations.
- Hands-on: attendees leave able to run the tools themselves
- Built on a real problem you have actually had to solve
- Vendor-neutral — no product pitches
- 45–90 minutes, any experience level clearly stated
Topics to be covered
Drawn from the terrain we teach people to defend — see Why It Matters. Pick one, or propose something adjacent.
Attack surface
Dependencies & registries
Dependency confusion, typosquatting, malicious packages on npm, PyPI and friends.
Build pipelines & CI/CD
Hardening the path from commit to release — isolation, secrets, runner security.
Provenance & artifact integrity
Signing, attestations and verifying what actually built an artifact.
Transitive dependencies
Seeing and managing the dependencies of your dependencies.
Vendor & third-party risk
Assessing the software and services you rely on but don’t control.
Bills of materials
SBOM generation & consumption
CycloneDX / SPDX — producing, augmenting and actually using an SBOM.
Cryptographic BOM (CBOM)
Inventorying the cryptography in your stack.
AI / ML BOM
Model, dataset and training-pipeline provenance for AI systems.
VEX & vulnerability triage
Turning a bill of materials into decisions about what to fix.
Standards & tooling
SLSA & Sigstore
Build levels, cosign, in-toto — putting provenance into practice.
OpenSSF Scorecard & S2C2F
Measuring and governing open-source consumption.
GUAC & supply chain graphs
Aggregating SBOM, SLSA and vulnerability data into something queryable.
Package monitoring & automation
Detecting malicious packages and scaling checks across many repos.
Regulation & readiness
EU CRA, NIST SSDF, EO 14028
What the regulations actually require from engineering teams.
NIS2 & DORA
Operational resilience obligations for critical and financial sectors.
Post-quantum & crypto agility
Harvest-now-decrypt-later and preparing the supply chain to migrate.
Incidents & industry
Real-world case studies
SolarWinds, Log4Shell, xz Utils, Shai-Hulud, PyTorch, Axios — what went wrong and how to catch it.
Sector-specific risk
Semiconductors, pharma, automotive, energy, telecom, finance, aerospace & defence.
Propose a talk or workshop
We program on the merits — no pay-to-speak. If you have something practical to show, pitch it.