Software Supply Chain Security: Open Source, SBOM, and Defending the Build Pipeline
Ankur Bhargava
Head of Product Security @ PhonePe
Moderator

Panel Overview
Supply chain attacks have proven devastatingly effective — compromise one dependency, build tool, or CI/CD pipeline and the payload reaches thousands of organizations simultaneously. SolarWinds, XZ Utils, and compromised npm/PyPI packages have permanently changed how security teams think about trust boundaries. This panel is composed entirely of practitioners and researchers who work on this problem daily: a founder building open-source supply chain security tooling (SafeDeep), a researcher who studies how software supply chains fail and sits on the Black Hat and Nullcon review boards (Cyfinoid Research), and the founder of PodArmor whose singular mission is software supply chain security — moderated by PhonePe's Head of Product Security managing this risk at fintech scale.
Meet the Panel

Ankur Bhargava
Head of Product Security @ PhonePe

Abhisek Datta
Founder @ SafeDep

Anant Shrivastava
Founder @ Cyfinoid Research

Nikhil Prabhakar
Founder @ PodArmor