Paul Novarese
Links &c
Selected Conference Talks/Presentations
- Among Us: They're in the Open Source Supply Chain
- [BSides Nashville, 2026-05-15]
[slides]
(no recording available)
- Are the Bad Guys Already in Your Software Supply Chain? (Spoiler Alert: Yes)
- A New XZ Every Day: The Nightmare Future of Open Source Supply Chains is Already Here
- From Log4j to XZ: Unsolvable Issues in the Software Supply Chain
- The Legacy of Log4Shell and the Future of DevSecOps (with bonus XZ content)
- [Texas Linux Fest, 2024-04-13] (no recording available)
[sildes]
- The Legacy of Log4Shell and the Future of DevSecOps
- [DevOpsDays Chattanooga, 2023-11-15] (no recording available)
[slides]
- The Lessons of Log4Shell
- SBOM Content, Usefulness, and Caveats (Panel)
- Learn From Log4Shell: Using SBOMs for Zero-Day Preparedness
- Secure Your Supply Chain: Adding a Software Bill of Materials to Your Containers to Improve Vulnerability Scanning
- User Namespace and Seccomp Support in Docker Engine
Papers, Reports, Reading Material &c
Upcoming
- The Phantom of the Open Source Supply Chain (TBD)
- Unrestricted Warfare: China's Software Dominance in Open Source Software (TBD)
Interviews
Other Appearances (Sponsored Talks, Webinars, &c)
Last update: 07:10 CDT6CST 2025-12-12