BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//open-source-conference-luxembourg-2026//sp
 eaker//RD8HD9
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251007T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Securing the Software Lifecycle: An Open-Source GitLab-Based DevSe
 cOps Demonstrator - Pierrick Pochelu
DTSTART;TZID=Europe/Luxembourg:20261007T153000
DTEND;TZID=Europe/Luxembourg:20261007T160000
DTSTAMP:20260916T160852Z
UID:pretalx-open-source-conference-luxembourg-2026-VBXSMA@pretalx.com
DESCRIPTION:Did you know that nearly 1 in 3 breaches comes from software v
 ulnerability exploitation? Surpassing stolen credentials as the leading in
 itial access vector. [1]\n\nSoftware vulnerabilities can be exploited acro
 ss multiple layers\, including source code\, software supply chains\, and 
 runtime environments. Securing individual components is no longer sufficie
 nt. Security must span the entire software lifecycle\, from development an
 d build processes to deployment and production operations.\n\nThis talk pr
 esents an open-source DevSecOps demonstrator built on GitLab CI/CD that in
 tegrates security controls from code commit to production runtime. The dem
 onstrator combines:\n\n* Development Security tools: SAST\, DAST\, Secret 
 Detection\,...\n* Software Supply Chain Security: cryptographic signing\, 
 verification\n* Runtime Security:  Web Application Firewall (WAF) protecti
 on\, and Runtime Application Self-Protection (RASP)\, binary hardening.\n
 \n\nThrough practical demonstrations and real pipeline executions\, attend
 ees will see how development security\, software supply chain security\, a
 nd runtime protection can be automated using widely available open-source 
 technologies. The session also shows how these controls map to industry-re
 cognized frameworks such as NIST SSDF\, OWASP SAMM\, and OWASP Secure Prod
 uct Design Principles.\n\nWhether you are a developer\, DevOps engineer\, 
 security practitioner\, or architect\, this talk provides a practical and 
 reproducible blueprint for building lifecycle-wide DevSecOps pipelines and
  strengthening software supply chain resilience without relying on proprie
 tary security platforms.\n\nDemonstrator URL : https://gitlab.seanergys.fz
 -juelich.de/pochelu1/devsecops_demonstrator\n\nThis work was supported by 
 EuroHPC JU SEANERGYS (g.a. 101177590).\n\n[1] https://www.verizon.com/busi
 ness/resources/reports/dbir/
LOCATION:Workshops Room 2
URL:https://pretalx.com/open-source-conference-luxembourg-2026/talk/VBXSMA
 /
END:VEVENT
END:VCALENDAR
