Loading…
Monday April 13, 2026 3:00pm - 4:30pm PDT
Many PowerShell authors think of their work as automation rather than software. But once a script is versioned, shared, or published, it becomes part of a supply chain. The same practical guardrails that protect applications can protect automation too, without turning your workflow upside down.

Most supply chain security conversations start at the registry. Signing and distribution controls matter, but they assume the artifact being published is already trustworthy. This session focuses on what happens earlier: provenance before publish.

In Part 1, we will use GitHub Actions with open source tools such as PSScriptAnalyzer, Semgrep, Syft, and Grype to build a pipeline that scans for vulnerabilities, detects risky behavior, and surfaces findings directly in pull requests. We'll also touch on integrating with enterprise SCA and cloud security platforms, for ongoing monitoring.

In Part 2, we apply the same approach to Chocolatey packaging workflows, validating naming, enforcing checksums, analyzing install scripts, and generating SBOMs for embedded OSS binaries before a package reaches a repository.

You will leave with forkable GitHub Actions and a practical model for securing supply chains from the pipeline out. You do not need a security background to follow along.
Speakers
avatar for Adil Leghari

Adil Leghari

Senior Solutioneer, Palo Alto Networks
Adil Leghari is a Sysadmin-turned-Solutioneer who is super-passionate about PowerShell and automation. He is currently a Senior Solutioneer at Palo Alto Networks. He’s active in the PowerShell community Slack and Discord servers. When not working, he enjoys designing PowerShell... Read More →
Monday April 13, 2026 3:00pm - 4:30pm PDT
Meydenbauer Center - Room 405 11100 NE 6th St, Bellevue, WA 98004, USA

Attendees (8)


Sign up or log in to save this to your schedule, view media, check-in, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link