Loading…
18-19 June
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon India 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in India Standard Time (UTC+5:30)To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Friday June 19, 2026 10:00am - 10:10am IST
We have been coming to KubeCon for ten years and talking about supply chain security for at least five of those years. We know the attacks and the mitigations. We have the frameworks, the SBOM attestations and the CNCF projects.

So why are the houses still burning?

That is what this talk is about. Not the tools, you know the tools. The gap between knowing and doing. And what happens when AI arrives on both sides of that gap at the same time.

Every security vulnerability comes with a score. But no severity score captures what it costs to be the person who reads that advisory at two in the morning, maintaining a project in the hours between their actual job and life, for a community that depends on them.

GitHub RCE, Trivy supply chain attack, tj-actions compromise, the xz backdoor. CVSS rankings from High to Critical. And behind every one, a human.

Every technological wave has done this. Humans absorb the cost.

The CNCF TAG DevEx survey of nearly 100 projects confirms top concerns of maintainers include security vulnerabilities and the burden caused by a potential flood of low-effort PRs and issues.

This talk traces the human cost across real incidents, asks why the pattern keeps repeating, and explores what it would take to finally break it.

Key takeaways include empathy for the maintainers along with a demo of how the same AI could be used to help maintainers know whether a published CVE affects their project and to what extent.
Speakers
avatar for Sonali Srivastava

Sonali Srivastava

Senior Developer Advocate, Improving
Sonali Srivastava is a Senior Developer Advocate at Improving, Co-chair KubeCon India 2026, and Co-organizer CNCF Women in Cloud Native. With experience across system administration, open source contribution and developer advocacy, she focuses on bridging gap between developers and... Read More →
Friday June 19, 2026 10:00am - 10:10am IST
Jasmine 2 (Level 3)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link