Ed Holloway-George

Lead Android Developer @ ASOS | Android GDE

Talk Title

How to stop the ‘Gradle Snatchers’: Securing your builds from baddies

Room

Salle Blin

Date

25.04.2024

Time

11:30 > 45 min

Share

on Twitter

Following on from one of the first recorded supply chain attacks against Gradle, this talk will discuss the security concerns surrounding our favourite build tool and how we can protect against them. This starts with gaining an understanding of some of Gradle's common vulnerabilities and how to avoid these within our projects. You'll leave this talk with:

- Insights on the Gradle Wrapper supply-chain attack and how to protect against it.
- An overview of a Gradle dependency attack and how to protect against them.
- A concrete list of security setting best practices within Gradle, including wrapper verification, repository filtering, dependency verification and others.

Speaker Bio

Ed Holloway-George is an Android Developer and Google Developer Expert originally from Oxford, UK but now currently residing in Nottingham, UK.

An Android developer for over 10 years; Ed now works for ASOS as a Lead Developer having previously worked on well-known applications such as National Trust, My Oxfam, Snoop, Carling Tap and many more.

In his spare time, Ed can be found tweeting and posting pictures of his dog.

Menu