With endless open-source dependencies, one bad package ripples widely. Learn production-grade defense using lessons from Dependabot.

Speakers

Eshaan Jain
Ankit Honey

Agenda

19:00 - Phase 1: - The Reality of Supply Chain Risk at Scale

  • Unpacking the dependency graph: Direct vs. transitive risk ripples.
  • Production mechanics: Why traditional vulnerability management breaks down at the ecosystem scale.

19:10 - Phase 2: Hands-On Triage & Context-Driven Prioritization

  • Moving beyond raw CVE counts: Evaluating vulnerabilities by actual exploitability and reachability.
  • Practical triage scenario: Walking through real-world dependency vulnerabilities (lessons from Dependabot data).

19:25 - Phase 3: Designing Automated Response Workflows (NIST SSDF Alignment).

  • Architecting the response loop: Automated alerts to continuous security updates.
  • Mapping automated playbooks directly to the NIST SSDF components (e.g., responding to vulnerabilities efficiently).

19:45 - Phase 4: AI Coding Agents in Supply Chain Defense.

  • The Hype vs. Reality: Where AI agents autonomously remediate code safely.
  • The Failure Modes: Hallucinations, breaking changes, and why human verification remains critical.

19:55 - Phase 5: Interactive Q&A & Framework Handoff

  • Open floor discussion with the community.
  • Distribution of the framework-aligned automated playbook resource.

Synopsis

Modern applications are mostly code you didn't write, with hundreds of transitive open-source dependencies, and a single compromised package can ripple through thousands of downstream systems. Drawing on practical lessons and real-world mechanics from running Dependabot, this hands-on session moves beyond the theory of supply chain risk into production-grade defense.

Attendees will learn how to triage and remediate risks based on severity and exploitability rather than chasing raw CVE counts, map automated workflows directly to the NIST Secure Software Development Framework (SSDF), and leave with a framework-aligned playbook. We will also provide a clear-eyed analysis of exactly where AI coding agents excel in supply chain defense—and where they fall short.

About the speakers

Eshaan Jain is a senior enterprise product leader with over 13 years of experience at the intersection of AI/ML, Quote-to-Cash (CPQ), and Contract Lifecycle Management (CLM). Currently serving as a Salesforce Product Owner at T-Mobile (via Mphasis), he leads the product strategy for the company's national B2B, Government, and Education platforms. In this role, he has designed over 32 complex custom capabilities, driving an estimated $20M+ in annual revenue impact.

Prior to his work at T-Mobile, Eshaan spent nearly five years at Amazon (2020–2025) as a Salesforce Technical Product Manager. He was responsible for the Global Supply Chain Transportation Procurement (GSCTP) platform, where he managed a $40B annual procurement spend and led the digital transformation of Amazon's entire last-mile transportation contract lifecycle. Eshaan's career also includes foundational leadership roles at PricewaterhouseCoopers (PwC) and Accenture, specializing in Salesforce assurance and IT controls.

He is a 5x Salesforce Certified professional and has been a 2x nominated Speaker at Dreamforce, Salesforce's flagship global event. In addition to his corporate achievements, Eshaan is an active researcher in AI and Machine Learning. He has published three peer-reviewed papers in IEEE and Elsevier journals. He holds a Master of Science in Computer Science from the University of Southern California (USC) and a B.Tech in Computer Science from GGSIPU in Delhi, India.

Ankit Kumar Honey is a Senior Engineering Manager at GitHub (Microsoft), where he leads the Dependabot team within the Supply Chain Security organisation. Dependabot is the most widely adopted open-source dependency management tool in the world, serving over 180 million developers across 20+ package ecosystems.

With 12+ years of experience spanning Amazon Web Services, Verizon, Toshiba, and Wipro, Ankit specialises in building large-scale security automation systems at the intersection of AI, developer productivity, and software supply chain integrity.

He is currently pursuing a Master's degree in Data Science at Harvard University Extension School, with a focus on AI, and holds a B.E. in Computer Science from Savitribai Phule Pune University. Speaking Profile - https://sessionize.com/ankithoney/

Our events are for adults aged 16 years and over.

This meeting is conducted in accordance with the BCS Code of Conduct for Meetings.

BCS is a membership organisation. If you enjoy this event, please consider joining BCS. You’ll be very welcome. You’ll receive access to many exclusive career development tools, an introduction to a thriving professional community and also help us Make IT Good For Society. Join BCS today

BCS privacy notice: your data will be processed by BCS in accordance with our data privacy notice.

Photography: by attending this event, you may be photographed or filmed. Please speak to a member of staff if you do not wish to be included.

This event is brought to you by: Open Source member group

Image Credit: Fly D

Operationalizing Software Supply Chain Security at Ecosystem Scale
Date and time
Thursday 29 October, 7:00pm - 8:00pm
Location

Webinar
Price
Free