Paul Novarese
Links &c
Selected Conference Talks/Presentations
- Are the Bad Guys Already in Your Software Supply Chain? (Spoiler Alert: Yes) (BSides Seattle, 2025-04-18) [slides]
- A New XZ Every Day: The Nightmare Future of Open Source Supply Chains is Already Here (BSides SLC, 2025-04-11) [slides]
- From Log4j to XZ: Unsolvable Issues in the Software Supply Chain (BSides RedRocks, 2024-11-15) (BSides Austin, 2024-12-05) [slides]
- The Legacy of Log4Shell and the Future of DevSecOps (Texas Linux Fest, 2024-04-13) [sildes] (no recording available)
- The Legacy of Log4Shell (DevOpsDays Chattanooga, 2023-11-15) [slides] (no recording available)
- The Lessons of Log4Shell (BSides RDU, 2023-09-22) [slides]
- The Lessons of Log4Shell (DevOpsDays DC, 2023-09-14) [slides]
- Panel: SBOM Content, Usefulness, and Caveats (FOSDEM, 2023-02-05) (and OpenSSF Recap)
- Learn From Log4Shell: Using SBOMs for Zero-Day Preparedness (DevOpsDays Houston, 2022-10-04; DevOpsDays Chattanooga, 2022-11-14) [slides]
- Secure Your Supply Chain: Adding a Software Bill of Materials to Your Containers to Improve Vulnerability Scanning (Open Source Summit Seattle, 2021-09-29) [slides]
- User Namespace and Seccomp Support in Docker Engine (ContainerCon Toronto, 2016-08-24; ContainerCon Berlin, 2016-10-04) [slides]
Papers, Reports, Reading Material &c
Upcoming
- Searching for the Next Jia Tan in the Open Source Supply Chain (BSides Montreal, 2025-09-13)
- Open Source Supply Chain Security is National Security (Threatcon1, 2025-09-22)
- Among Us: They're in the Open Source Supply Chain (BSides Orlando, 2025-09-27)
Interviews
Other Appearances (Sponsored Talks, Webinars, &c)
Last update: 20:50 CDT6CST 2025-06-27