diff --git a/website/content/posts/devconf-us-2026-talk.md b/website/content/posts/devconf-us-2026-talk.md new file mode 100644 index 00000000..8accc8b3 --- /dev/null +++ b/website/content/posts/devconf-us-2026-talk.md @@ -0,0 +1,32 @@ +--- +title: "DevConf.US 2026: Closing the Gap Between Build Evidence and Compliance Enforcement" +date: 2026-09-24T10:40:00-04:00 +author: "Cuiping Huo & Simon Baird" +--- + +We're excited to share that Conforma was featured at DevConf.US 2026. The talk tackles a gap many teams run into: you collect plenty of build evidence — SBOMs, SLSA provenance, signatures, attestations — but that evidence doesn't enforce anything on its own. + + + +## The Challenge: Evidence Without Enforcement + +Modern build systems produce a wealth of security metadata. The hard part is turning that data into decisions: which images are allowed to ship, and why? Without enforcement, a signed image still isn't a *trusted* image — the signature only tells you who built it, not whether it meets your policies. + +## Closing the Gap with Policy-as-Code + +The talk works through a series of live demos that build up from the basics to real-world policy enforcement with Conforma: + +- Validating structured data against a policy written in Rego +- Validating a real, signed container image — and catching a source-correlation attack where the signature is valid but the source doesn't match +- Writing one custom rule that different teams tune through `ruleData`, no rule changes required +- Using `effective_on` to roll out a new rule as a warning first, so teams get a grace period before it becomes a hard failure + +Each demo is small and self-contained, showing how Conforma turns build evidence into enforceable, auditable decisions. + +## Watch the Talk + +The recording, slides, and demo repository are now available on our Resources page. + +**[Watch "Closing the Gap Between Build Evidence and Compliance Enforcement"](/resources/#closing-the-gap-between-build-evidence-and-compliance-enforcement)** + +While you're there, explore our collection of other conference presentations, demos, and educational content about securing software supply chains with Conforma. diff --git a/website/content/resources/_index.md b/website/content/resources/_index.md index 35910417..9f4f048d 100644 --- a/website/content/resources/_index.md +++ b/website/content/resources/_index.md @@ -6,6 +6,30 @@ Whether you're just getting started with supply chain security or looking to dee These conference presentations, demos, educational videos and articles showcase how organizations are using Conforma to secure their software supply chains. +## Closing the Gap Between Build Evidence and Compliance Enforcement + +**Speakers:** Cuiping Huo & Simon Baird, Red Hat +**Event:** DevConf.US 2026 +**Format:** Conference Talk with Live Demo +**Link:** [Watch on YouTube](https://www.youtube.com/live/wBda6wMuLaQ?t=2800) +**Slides:** [View presentation](https://github.com/cuipinghuo/devconf-us-2026/blob/main/slides.pdf) +**Git:** [Open demo git repository](https://github.com/cuipinghuo/devconf-us-2026) + +{{< rawhtml >}} +
+ +
+{{< /rawhtml >}} + +Build systems produce plenty of security evidence — SBOMs, SLSA provenance, signatures, attestations — but that evidence doesn't enforce anything on its own. This talk shows how Conforma closes that gap with policy-as-code, through a series of live demos that build from the basics to real-world enforcement (the talk starts at 46:40 in the recording). This talk covers: + +- Validating structured data against a Rego policy with `ec validate input` +- Validating a real signed container image, and catching a source-correlation attack where the signature is valid but the source doesn't match +- Writing one custom rule that different teams tune through `ruleData` +- Rolling out a rule as a warning first with `effective_on`, giving teams a grace period before it becomes a hard failure + +*Great for anyone who has build evidence but wants to turn it into enforceable, auditable decisions.* + ## From SBOM to Enforcement: Writing License Policies with Conforma **Speaker:** Luiz Carvalho, Red Hat