Loading…
Type: Security clear filter
Monday, April 13
 

3:00pm PDT

DevSecOps with GitHub Advanced Security (GHAS)
Monday April 13, 2026 3:00pm - 4:30pm PDT
DevSecOps tries to make DevOps teams aware about integrating security into each and every step of the process. But this is complex, with a need to integrate a whole set of tools. But no more, thanks to GitHub Advanced Security, baked into your trusted DevOps environment. In this session, Peter will guide you through a full range of built-in GitHub security features, ranging from branch policies over code scanning, security vulnerability scanning with Dependabot and CodeQL, how to enable it, how to use it and how to interpret the reporting.
Speakers
avatar for Peter De Tender

Peter De Tender

Microsoft Technical Trainer, Microsoft
Peter has an extensive background in architecting, deploying, managing and training Microsoft technologies, dating back to Windows NT4 Server in 1996, all the way to the latest and modern cloud solutions available in Azure today. With a passion for cloud Architecture, Devops and Security... Read More →
Monday April 13, 2026 3:00pm - 4:30pm PDT
Meydenbauer Center - Room 406 11100 NE 6th St, Bellevue, WA 98004, USA

3:00pm PDT

Provenance Before Publish: Building Safer PowerShell and Chocolatey Pipelines
Monday April 13, 2026 3:00pm - 4:30pm PDT
Many PowerShell authors think of their work as automation rather than software. But once a script is versioned, shared, or published, it becomes part of a supply chain. The same practical guardrails that protect applications can protect automation too, without turning your workflow upside down.

Most supply chain security conversations start at the registry. Signing and distribution controls matter, but they assume the artifact being published is already trustworthy. This session focuses on what happens earlier: provenance before publish.

In Part 1, we will use GitHub Actions with open source tools such as PSScriptAnalyzer, Semgrep, Syft, and Grype to build a pipeline that scans for vulnerabilities, detects risky behavior, and surfaces findings directly in pull requests. We'll also touch on integrating with enterprise SCA and cloud security platforms, for ongoing monitoring.

In Part 2, we apply the same approach to Chocolatey packaging workflows, validating naming, enforcing checksums, analyzing install scripts, and generating SBOMs for embedded OSS binaries before a package reaches a repository.

You will leave with forkable GitHub Actions and a practical model for securing supply chains from the pipeline out. You do not need a security background to follow along.
Speakers
avatar for Adil Leghari

Adil Leghari

Senior Solutioneer, Palo Alto Networks
Adil Leghari is a Sysadmin-turned-Solutioneer who is super-passionate about PowerShell and automation. He is currently a Senior Solutioneer at Palo Alto Networks. He’s active in the PowerShell community Slack and Discord servers. When not working, he enjoys designing PowerShell... Read More →
Monday April 13, 2026 3:00pm - 4:30pm PDT
Meydenbauer Center - Room 405 11100 NE 6th St, Bellevue, WA 98004, USA
 
Wednesday, April 15
 

2:45pm PDT

Open Packages are Overpowered
Wednesday April 15, 2026 2:45pm - 3:30pm PDT
NuGet and Chocolatey are a lot more tasty than you might think.

For example, did you know we can turn any package into a web server? That's pretty sweet! We can also scan them to see what's inside without it harming us (also pretty sweet).

In this talk, we'll go over some of the overpowered things you can do with Open Packages like NuGet, Chocolatey, and PowerShell Gallery Modules.
Speakers
Wednesday April 15, 2026 2:45pm - 3:30pm PDT
Meydenbauer Center - Room 407 11100 Northeast 6th Street, Bellevue, WA, USA
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.