We’re running the Supply Chain Security Village at c0c0n 2026 — 9–10 October, Kochi, IndiaEvent page

Talks & Workshops

Talks & Workshops

Technical sessions from people who do this work — not vendor keynotes. Talks explain and demonstrate real supply-chain attacks and the defences that hold up. Workshops are hands-on.

Live demos, not slideware

Attacks and defences run in front of you, reproducible step by step — not screenshots of someone else’s terminal.

Hands-on workshops

You leave able to run the tools yourself: generate an SBOM, sign an artifact, harden a pipeline.

Vendor-neutral

Practitioners explaining how things actually work. No product pitches, no sponsor-shaped talks.

Topics we cover

The through-line is always the same: where software gets compromised on its way from source to production, and how to catch it.

SBOM generation & consumption

CycloneDX, SPDX, and what to do with a bill of materials once you have one.

Provenance & signing

SLSA, Sigstore, cosign, in-toto — proving what built an artifact and that it wasn’t tampered with.

CI/CD hardening

Build-system isolation, secret handling, and locking down the path from commit to release.

Dependency & registry attacks

Dependency confusion, typosquatting, and malicious packages on npm, PyPI, and friends.

Post-quantum & crypto-agility

What crypto agility means for the supply chain, and how to inventory what needs to change.

AI/ML supply chain

Model and dataset provenance, ML-BOM, and the new attack surface that ships with AI systems.

Archive

Sessions are published here after each edition — title, speaker, abstract, and slides or video where available.

First edition — coming soon

The inaugural line-up is being assembled. Once talks are confirmed they’ll appear here, grouped by event and year.

c0c0n 2026 · 9–10 October · Kochi

Call for Workshops

We’re looking for practitioners to run hands-on workshops at the Village. Practical problems, real tools, working code — not slide-heavy presentations.

  • Hands-on: attendees leave able to run the tools themselves
  • Built on a real problem you have actually had to solve
  • Vendor-neutral — no product pitches
  • 45–90 minutes, any experience level clearly stated
Propose a workshop

Topics to be covered

Drawn from the terrain we teach people to defend — see Why It Matters. Pick one, or propose something adjacent.

Attack surface

Dependencies & registries

Dependency confusion, typosquatting, malicious packages on npm, PyPI and friends.

Build pipelines & CI/CD

Hardening the path from commit to release — isolation, secrets, runner security.

Provenance & artifact integrity

Signing, attestations and verifying what actually built an artifact.

Transitive dependencies

Seeing and managing the dependencies of your dependencies.

Vendor & third-party risk

Assessing the software and services you rely on but don’t control.

Bills of materials

SBOM generation & consumption

CycloneDX / SPDX — producing, augmenting and actually using an SBOM.

Cryptographic BOM (CBOM)

Inventorying the cryptography in your stack.

AI / ML BOM

Model, dataset and training-pipeline provenance for AI systems.

VEX & vulnerability triage

Turning a bill of materials into decisions about what to fix.

Standards & tooling

SLSA & Sigstore

Build levels, cosign, in-toto — putting provenance into practice.

OpenSSF Scorecard & S2C2F

Measuring and governing open-source consumption.

GUAC & supply chain graphs

Aggregating SBOM, SLSA and vulnerability data into something queryable.

Package monitoring & automation

Detecting malicious packages and scaling checks across many repos.

Regulation & readiness

EU CRA, NIST SSDF, EO 14028

What the regulations actually require from engineering teams.

NIS2 & DORA

Operational resilience obligations for critical and financial sectors.

Post-quantum & crypto agility

Harvest-now-decrypt-later and preparing the supply chain to migrate.

Incidents & industry

Real-world case studies

SolarWinds, Log4Shell, xz Utils, Shai-Hulud, PyTorch, Axios — what went wrong and how to catch it.

Sector-specific risk

Semiconductors, pharma, automotive, energy, telecom, finance, aerospace & defence.

Propose a talk or workshop

We program on the merits — no pay-to-speak. If you have something practical to show, pitch it.