BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//program.wiccon.nl//YTMLW9
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-wiccon-2026-YTMLW9@program.wiccon.nl
DTSTART;TZID=CET:20261029T103000
DTEND;TZID=CET:20261029T112000
DESCRIPTION:I am going to talk about software supply chain security\, more 
 precisely about exploiting CI/CD pipelines in GitHub so as to publish mali
 cious versions of popular open source packages (just for example\, on npmj
 s)\, write arbitrary code in GitHub repos or steal secrets.
DTSTAMP:20260922T183841Z
LOCATION:Main Hall
SUMMARY:How to capitalise on other people’s popularity to distribute malw
 are: Weaponizing CI/CD Pipelines - Garance
URL:https://program.wiccon.nl/wiccon-2026/talk/YTMLW9/
END:VEVENT
END:VCALENDAR
