With endless open-source dependencies, one bad package ripples widely. Learn production-grade defense using lessons from Dependabot.
Speakers
Eshaan Jain
Ankit Honey
Agenda
19:00 - Phase 1: - The Reality of Supply Chain Risk at Scale
- Unpacking the dependency graph: Direct vs. transitive risk ripples.
- Production mechanics: Why traditional vulnerability management breaks down at the ecosystem scale.
19:10 - Phase 2: Hands-On Triage & Context-Driven Prioritization
- Moving beyond raw CVE counts: Evaluating vulnerabilities by actual exploitability and reachability.
- Practical triage scenario: Walking through real-world dependency vulnerabilities (lessons from Dependabot data).
19:25 - Phase 3: Designing Automated Response Workflows (NIST SSDF Alignment).
- Architecting the response loop: Automated alerts to continuous security updates.
- Mapping automated playbooks directly to the NIST SSDF components (e.g., responding to vulnerabilities efficiently).
19:45 - Phase 4: AI Coding Agents in Supply Chain Defense.
- The Hype vs. Reality: Where AI agents autonomously remediate code safely.
- The Failure Modes: Hallucinations, breaking changes, and why human verification remains critical.
19:55 - Phase 5: Interactive Q&A & Framework Handoff
- Open floor discussion with the community.
- Distribution of the framework-aligned automated playbook resource.
Synopsis
Modern applications are mostly code you didn't write, with hundreds of transitive open-source dependencies, and a single compromised package can ripple through thousands of downstream systems. Drawing on practical lessons and real-world mechanics from running Dependabot, this hands-on session moves beyond the theory of supply chain risk into production-grade defense.
Attendees will learn how to triage and remediate risks based on severity and exploitability rather than chasing raw CVE counts, map automated workflows directly to the NIST Secure Software Development Framework (SSDF), and leave with a framework-aligned playbook. We will also provide a clear-eyed analysis of exactly where AI coding agents excel in supply chain defense—and where they fall short.
About the speakers
Eshaan Jain is a senior enterprise product leader with over 13 years of experience at the intersection of AI/ML, Quote-to-Cash (CPQ), and Contract Lifecycle Management (CLM). Currently serving as a Senior Product Manager at a leading management consulting firm. Before that, Eshaan spent nearly five years at Amazon (2020–2025) as a Salesforce Technical Product Manager, where he managed large-scale supply chain procurement platforms and led the digital transformation of enterprise contract lifecycles. His career also includes foundational leadership roles at PricewaterhouseCoopers (PwC) and Accenture, specializing in Salesforce assurance and IT controls.
Beyond his corporate achievements, Eshaan is an active researcher in AI and machine learning and has published three peer-reviewed papers in IEEE and Elsevier journals. He holds an M.S. in Computer Science from the University of Southern California (USC).
Ankit Kumar Honey is a Senior Engineering Manager at GitHub (Microsoft), where he leads the Dependabot team within the Supply Chain Security organisation. Dependabot is the most widely adopted open-source dependency management tool in the world, serving over 180 million developers across 20+ package ecosystems.
With 12+ years of experience spanning Amazon Web Services, Verizon, Toshiba, and Wipro, Ankit specialises in building large-scale security automation systems at the intersection of AI, developer productivity, and software supply chain integrity.
He is currently pursuing a Master's degree in Data Science at Harvard University Extension School, with a focus on AI, and holds a B.E. in Computer Science from Savitribai Phule Pune University. Speaking Profile - https://sessionize.com/ankithoney/
The views and opinions expressed in this event and description are those of the speaker and do not necessarily reflect the official policy or position of any employer or client.
Our events are for adults aged 16 years and over.
This meeting is conducted in accordance with the BCS Code of Conduct for Meetings.
BCS is a membership organisation. If you enjoy this event, please consider joining BCS. You’ll be very welcome. You’ll receive access to many exclusive career development tools, an introduction to a thriving professional community and also help us Make IT Good For Society. Join BCS today
BCS privacy notice: your data will be processed by BCS in accordance with our data privacy notice.
Photography: by attending this event, you may be photographed or filmed. Please speak to a member of staff if you do not wish to be included.
This event is brought to you by: Open Source member group
Image Credit: Fly D