Software supply chain incidents continue to evolve, and knowing how to protect your organization before, during, and after an incident is becoming increasingly important.
In this workshop, we’ll look at the latest supply chain trends and walk through practical ways teams can reduce their exposure and respond when new threats emerge.
Using Semgrep, we’ll cover how to prevent AI agents from downloading malicious packages, enforce package cooldown periods, secure GitHub Actions by pinning them to commit SHAs, and quickly alert teams when a new supply chain incident is identified. We’ll also show how to determine which projects are impacted so teams can prioritize investigation and remediation.
You’ll leave with practical workflows you can apply to strengthen your software supply chain before the next incident hits.