Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions website/content/posts/devconf-us-2026-talk.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
title: "DevConf.US 2026: Closing the Gap Between Build Evidence and Compliance Enforcement"
date: 2026-09-24T10:40:00-04:00
author: "Cuiping Huo & Simon Baird"
---

We're excited to share that Conforma was featured at DevConf.US 2026. The talk tackles a gap many teams run into: you collect plenty of build evidence — SBOMs, SLSA provenance, signatures, attestations — but that evidence doesn't enforce anything on its own.

<!--more-->

## The Challenge: Evidence Without Enforcement

Modern build systems produce a wealth of security metadata. The hard part is turning that data into decisions: which images are allowed to ship, and why? Without enforcement, a signed image still isn't a *trusted* image — the signature only tells you who built it, not whether it meets your policies.

## Closing the Gap with Policy-as-Code

The talk works through a series of live demos that build up from the basics to real-world policy enforcement with Conforma:

- Validating structured data against a policy written in Rego
- Validating a real, signed container image — and catching a source-correlation attack where the signature is valid but the source doesn't match
- Writing one custom rule that different teams tune through `ruleData`, no rule changes required
- Using `effective_on` to roll out a new rule as a warning first, so teams get a grace period before it becomes a hard failure

Each demo is small and self-contained, showing how Conforma turns build evidence into enforceable, auditable decisions.

## Watch the Talk

The recording, slides, and demo repository are now available on our Resources page.

**[Watch "Closing the Gap Between Build Evidence and Compliance Enforcement"](/resources/#closing-the-gap-between-build-evidence-and-compliance-enforcement)**

While you're there, explore our collection of other conference presentations, demos, and educational content about securing software supply chains with Conforma.
24 changes: 24 additions & 0 deletions website/content/resources/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,30 @@ Whether you're just getting started with supply chain security or looking to dee

These conference presentations, demos, educational videos and articles showcase how organizations are using Conforma to secure their software supply chains.

## Closing the Gap Between Build Evidence and Compliance Enforcement

**Speakers:** Cuiping Huo & Simon Baird, Red Hat
**Event:** DevConf.US 2026
**Format:** Conference Talk with Live Demo
**Link:** [Watch on YouTube](https://www.youtube.com/live/wBda6wMuLaQ?t=2800)
**Slides:** [View presentation](https://github.com/cuipinghuo/devconf-us-2026/blob/main/slides.pdf)
**Git:** [Open demo git repository](https://github.com/cuipinghuo/devconf-us-2026)

{{< rawhtml >}}
<br>
<iframe width="560" height="315" src="https://www.youtube.com/embed/wBda6wMuLaQ?start=2800" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
<br>
{{< /rawhtml >}}

Build systems produce plenty of security evidence — SBOMs, SLSA provenance, signatures, attestations — but that evidence doesn't enforce anything on its own. This talk shows how Conforma closes that gap with policy-as-code, through a series of live demos that build from the basics to real-world enforcement (the talk starts at 46:40 in the recording). This talk covers:

- Validating structured data against a Rego policy with `ec validate input`
- Validating a real signed container image, and catching a source-correlation attack where the signature is valid but the source doesn't match
- Writing one custom rule that different teams tune through `ruleData`
- Rolling out a rule as a warning first with `effective_on`, giving teams a grace period before it becomes a hard failure

*Great for anyone who has build evidence but wants to turn it into enforceable, auditable decisions.*

## From SBOM to Enforcement: Writing License Policies with Conforma

**Speaker:** Luiz Carvalho, Red Hat
Expand Down
Loading