BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.devconf.info//devconf-us-2026//talk//YRCUPB
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-devconf-us-2026-YRCUPB@pretalx.devconf.info
DTSTART;TZID=EST:20260924T104000
DTEND;TZID=EST:20260924T111500
DESCRIPTION:With many build systems now generating SBOMs\, SLSA provenance\
 , vulnerability reports\, etc\, we’ve never had more evidence about what
  goes into our software. But if there's nothing acting on the evidence gat
 hered\, our pipelines can still produce non-compliant artifacts.\n\nCollec
 ting evidence is important of course\, but looking at the evidence\, asses
 sing its correctness\, and evaluating compliance with business and securit
 y policies for each artifact produced\, is what really helps make our buil
 d systems more secure\, and lets us claim SLSA build levels\, and satisfy 
 NIST and EU regulations.\n\nIn this session\, we highlight the gap between
  generating build metadata\, and actually using it to block non-compliant 
 artifacts. We’ll walk through a realistic pipeline scenario where everyt
 hing looks compliant on paper — valid SBOM\, signed provenance\, clean s
 cans — and still it shouldn’t be deployed.\n\nFrom there\, we introduc
 e a different model: treating policies as active\, blocking gates that eva
 luate each artifact against organizational trust requirements and managed 
 policies.\n\nUsing Conforma\, an open-source Policy-as-Code engine\, we wi
 ll demonstrate how to:\n* Transform passive evidence (SPDX SBOMs\, SLSA pr
 ovenance) into enforceable decisions\n* Define and apply policies such as 
 trusted builders\, CVE thresholds\, and license compliance\n* Integrate po
 licy evaluation directly into CI/CD pipelines as promotion and deployment 
 gates\n* Move toward a Zero-Trust model where every artifact must prove it
 self before advancing\n\nYou’ll leave with a clear understanding of why 
 having the data isn’t the same as being secure\, and how to turn your su
 pply chain metadata into an enforced line of defense. We’ll demonstrate 
 this using a policy-as-code approach with Conforma.
DTSTAMP:20260727T165015Z
LOCATION:106 (Capacity 45)
SUMMARY:Closing the Gap Between Build Evidence and Compliance Enforcement -
  Simon Baird\, Cuiping Huo
URL:https://pretalx.devconf.info/devconf-us-2026/talk/YRCUPB/
END:VEVENT
END:VCALENDAR
