Skip to main content
Home

Main navigation

  • About
    • Program at a glance
    • Venue and rooms
    • Lunch
    • Contribution
    • Accomodation
    • FAQs
    • In the Media
    • Team
  • Schedule
    • Sessions Overview
    • Mautic Days
    • Venue map
  • Speakers
  • Sponsors
  • Tracks
User account menu
  • Log in
Event Platform Header CTA Pictures

Breadcrumb

  1. Home
  2. What is the secure software supply chain and the current state of the PHP ecosystem

What is the secure software supply chain and the current state of the PHP ecosystem

Room
HS4 (Ground level)
Time Slot
Fri 4:15pm to 5:00pm (7/21/23)
Session length
Long session - 45min, including Q&A
Audience
All Attendees
Session Category
DevOps & Quality Assurance

In this talk I’ll present the current state of the software supply chain, the big global recent events (SolarWinds, log4shell, codecov, packagist) and the state of the PHP and Drupal ecosystem, the threats and the mitigations that can be applied using tools like Sigstore, Syft, and Grype for digital signatures, SBOM generation, and automatic vulnerability scanning and how to use them for real-world projects to gain unprecedented levels of knowledge of your digital artifacts. 
There will be also a demo of the mentioned tools in action to implement a secure supply chain pipeline for your Drupal projects.

Speaker(s)
Profile picture for user paolo.mainardi

Paolo Mainardi

CTO at Sparkfabrik
Speaker biography

Hello, i am Paolo Mainardi, proud founder and CTO of Sparkfabrik.

My role is to drive the company toward innovation, by building cutting-edge and cloud-native web applications and doing Kubernetes consultancy at different levels, from the the cluster management to custom implementations, we are also CNCF Silver Member and Kubernetes Certified Service Provider (KCSP).

When i am not too busy with the company stuff, i like to contribute to open source projects, speaking and organizing conferences and actively participating to the community.

You can get in touch with me on Mastodon: https://continuousdelivery.social/@paolomainardi

Session Keywords
Security
Share:

Platinum Sponsors

Logo 1xinternet

Gold Sponsors

D shaped logo and the name Droptica
Logo AgileDrop
Logo Amazee.io

Silver Sponsors

Logo Kraut.Hosting GmbH
dropsolid logo
Logo EOR Digital GmbH
Logo Druid.fi

Media Partner

Logo Kurier.at
droptimes logo

Funded by

wko logo
Meeting Destination Vienna

Footer

  • Contact
  • Code of Conduct
  • Data Privacy
  • Media Policy
  • FAQs
  • Imprint

Copyright © Drupal Dev Days 2025. All rights reserved.

Webdesign by acolono GmbH, implementation by Alex Milkovskyi

Webhosting by amazee.io
Powered by Drupal