☕ Social📍 SydneyOpen to all

Killing CVEs at the Source: Supply Chain Security in Practice

WhenWed, Oct 14, 5:00 PMStarts in 12 days📅 Add to calendarWhereCuscal LimitedDarling Park Tower, 1/201 Sussex St, Sydney NSW 2000, Australia, Sydney🗺 Apple Maps🗺 Google Maps🚕 UberHostCNCF Cloud Native Sydney chapter (formerly DevSecOps Sydney)CostNot stated — check with the hostOneJoy doesn't handle payments — settle directly with the host or venue.CapacityOpen — no spot limit

About this event

Join us for an evening of insightful talks, valuable connections, and great company. One evening on what it actually takes to secure a software supply chain, from hardened container images through to what this looks like inside a regulated environment. Talk 1 - Engineering for a World Where Exploits Arrive Before the Advisory Speaker: Cameron Martin (Chainguard) Most teams meet their supply chain problem downstream, as a scanner report full of criticals and a patching queue that never empties. This talk looks at the other end of the pipeline: what changes when images are built minimal and rebuilt continuously, so vulnerabilities are removed at the source rather than triaged after they land in production. We'll cover the practical patterns teams are using for container hardening, how this plays with SBOMs, signing and provenance, and where it fits alongside your existing scanning and admission controls. Plus a forward look at the Chainguard roadmap and what's coming next. Talk 2 - Supply Chain Security in a Regulated Environment Speaker: Brad McCoy (Cuscal) The theory is one thing, running it inside an Australian financial services business is another. Brad shares what this looks like in practice at Cuscal: the platform decisions, the trade offs, and how container security and compliance requirements actually get met day to day without grinding delivery to a halt. An honest look at what worked, what didn't, and what he'd do differently. This is a relaxed, highly interactive evening built for platform engineers, security engineers, DevSecOps leaders and architects who are actively working through supply chain risk, container hardening and compliance. On the night: Free entry · Food & drinks · Networking · Live Q&A Seats are limited - RSVP to save your spot. See you there! 👋

Join this event

Before you join

OneJoy is where people find each other — the host organises the event, not us. Check who is hosting, judge whether it suits you, and take the same care you would meeting anyone new. Under-18s should come with a parent or guardian. Any money changes hands directly with the host; OneJoy never handles payments.

Sign in — Have an account? Sign in and we'll fill this in for you.

Only shared with the host.

More options

Questions & comments

Ask the host anything — replies are visible to everyone.

—

⚑ Report

Report this to the OneJoy team

Tell us what is wrong. We read every report.