DWeb Camp 2026

Supply Chain Security in FOSS
2026-07-11 , Hackers Lab

A quick tour of the rapidly evolving landscape of malicious dependencies, follow by hands on workshop setting up free-for-FOSS tool socket.dev


p2p applications necessarily have more local execution privileges than your average web app. This makes trusting the libraries you're building on especially important. The task of auditing this attack surface was already untenable, and LLM have massively compounded this - both discovering and creating new vulnerabilities with ease.

What should you watch for? How do you defend yourself? What does this mean for FOSS? I work for Socket Security, and will demo tools which can keep your work and communities safer. Bring a laptop and you can walk away more secure - we have free accounts to give out to every FOSS project.

Mix is from Wellington, New Zealand. He's worked in peer to peer indigenous projects (Ahau), on core protocols and community in Scuttlebutt, has contributed to deliberative tools (Loomio, Cobudget), and grown coops (Protozoa), has a background in radical education.

All in on collectivism. Loves sci-fi and magic the gathering.

This speaker also appears in: