Trust Nothing, Ship Safely: Surviving the Supply Chain Attack Era

Supply chain attacks are no longer a theoretical threat — they are a daily reality, with GitHub repositories, npm packages, VS Code extensions, and even the biggest open-source libraries increasingly weaponized to compromise thousands of developers and their users at once. In this talk, Nina will explore why anyone can fall victim to these attacks and, most importantly, what practical steps developers can take to reduce their exposure — not by becoming security experts, but by learning to ask one uncomfortable question about everything they depend on: why do I trust this?


