
Sponsored By:
Tuesday, October 13th
11 am ET
Modern builds pull thousands of open-source packages straight from public registries, and attackers have learned to poison them at the source. In response, the ecosystem has reached a rare consensus in under a year: release cooldowns. npm, pnpm, and pip have all shipped waiting periods before newly published versions can be installed, and CISA now explicitly recommends a minimum release age.
But while the industry agrees on the control, almost no organization can actually enforce it consistently.
The Problem:
Client-side settings are voluntary, differ across ecosystems, and depend on every repository, CI image, and AI agent being provisioned correctly. At organisational scale, hoping "everyone remembered" is not a security control. Even where vendors have built real enforcement, it is often locked to a single platform. Meanwhile, attacks keep arriving through signed, trusted release paths, and compliance clocks like CRA Article 14 now demand rigorous evidence of exactly what entered your builds and when.
Why You Should Attend
Join Mitch Ashely of The Futurum Group and Thijs Feryn of Varnish for a practical session on solving this enforcement gap. We will show you how to turn the industry consensus on release cooldowns into an airtight, automated organisational policy that covers your entire infrastructure, including:
- Enforce a single, unified policy: Learn how to apply one set of rules across every ecosystem and client, closing the gaps left by fragmented, vendor-siloed tools.
- Roll out without breaking builds: Discover practical strategies for implementing package-age security controls smoothly, without disrupting your CI/CD pipelines.
- Automate your compliance trail: See how to capture the exact decision data needed to confidently answer the 72-hour reporting question and prove compliance with CRA Article 14.
Register Below:
We'll send you an email confirmation

Thijs Feryn
Tech Evangelist - Varnish
Thijs Feryn is the Technical Evangelist at Varnish, the company behind the Varnish Cache open-source caching technology.
His mission is to bridge the gap between code and infrastructure, with a strong focus on web performance, software scalability, and content delivery. He shares technical and content-driven messaging across presentations, videos, books, blog posts, podcasts, and social media.

Mitch Ashley
VP & Practice Lead, Software Lifecycle Engineering - The Futurum Group
Mitch Ashley is Vice President and Practice Lead, Software Lifecycle Engineering for The Futurum Group. Mitch has over 30+ years of experience as an entrepreneur, industry analyst, product development and IT leader, with expertise in software engineering, cybersecurity, DevOps, DevSecOps, cloud, and AI. Mitch comes to The Futurum Group through the acquisition of Techstrong Group (devops.com, securityboulevard.com, and techstrong.tv), where he serves as CTO and founder of Techstrong Research.

Tom Hollingsworth
Event Lead - Tech Field Day
Tom Hollingsworth, is an event lead for the Tech Field Day events series. He also writes about networking and related technolgies on his blog. With over 18 years of experience in the IT field, Tom has covered the breadth of technology from desktop deployment to data center installation. He brings his unique perspective to his writing both on his blog and at Network Computing. Tom can also be found prognosticating and commenting about technology from his Twitter account.