Software Supply Chain Security and DevSecOps Trends with Sonatype’s Ilkka Turunen
Ilkka Turunen, Field CTO at Sonatype, discusses the importance of software supply chain security and his experience in the DevSecOps space. He also highlights the upcoming All Day DevOps event on Oct. 10, where Sonatype will release its 10th annual State of the Software Supply Chain report, addressing key issues such as malware in open source. Ilkka also mentions Sonatype’s From the Source video series, which focuses on current trends in DevSecOps and supply chain security.
Transcript
This is Text on tv. Hey everyone, welcome to another text, drug TV interview. I am really happy to be joined by my friend Ilkka Turin.
Ilkka is with Sony type. You know, if you watch text drug tv, you usually see Brian Fox from song type on, uh, on our channel. But every once in a while we get lucky and we get Ilkka to join us from over in Europe.
So today's one of those lucky days. Ilkka, how are you? And it's great to see you.
Hey, super, uh, happy to be, uh, to be here with you today. Um, I'm doing well. Fantastic.
I, I, I mentioned you're in Europe and obviously you're with Sonotype, but you know, I, that's kind of sketchy. Why don't you fill people in on the rest of your background and, and what you do with Sonotype? Yeah, no, for sure.
Um, so, uh, name's finished by the way, in case, uh, anyone's wondering. Uh, originally born and raised in Finland. Uh, moved to the UK where I'm based now, about 10 years ago, um, and about 20 pounds ago too.
Um, and, um, uh, and, uh, but you know, I don't look Like you've put on 20 pounds, so, wow. Well, you know, it kind of comes and goes, right? Mm-Hmm.
It comes and goes. Plus, um, uh, plus, um, you know, I've got a background essentially as a, as a software engineer. Started out, you know, coding whilst I was in uni, I kind of founded my first startup, got killed by the financial crisis and sort of fall through on that.
Um, and, you know, did a bunch of years doing sort of early DevOps transformation. So, um, so, um, um, I was quite involved, especially in London, in getting people away from sort of highly manual builds, starting to get them to moving into the cloud, sort of adopting and adopting sort of best practice in how do we get software out with a single committee into production. You know, observe early adoption of microservices and things like this.
And, uh, yeah, just around nine years ago I heard about this company, uh, called Cy that was all about, uh, all about social security vulnerabilities and open source. And I thought, what a c idea? Surely open source developers and maintainers, I know many of them have contributed code.
They're all super talented people. Surely they'll know not to distribute things with like known bad bugs. And, you know, if you've, uh, been in this industry for Last years.
Yeah, exactly. Ended up being pretty much, uh, pretty much, uh, sort of defining statements, uh, defining statement for the next decade of my life. Joined them early on.
Uh, got really involved in, uh, sort of doing early DevSecOps implementation. We kind of found a way of adding the security word into, uh, into sort of the DevOps and cloud transformation projects that we were doing. And that really opened up this sort of new cornucopia of interesting things.
I, as a software developer, I like always thought that dependency management was the most boring thing you could do. 'cause it takes so long finding libraries they never work. Frameworks always got of, uh, out of, uh, fashion and, you know, out of maintenance.
But, uh, here I am nine years later thinking about nothing but dependencies in supply chain, uh, type things, uh, when, when it comes to that. So today I'm the field CTO, um, uh, out of Europe, uh, for Sonatype. So I lead run our global solutions architecture team.
I worked with Brian quite a lot actually on some of our research, uh, arm. We've talked to regulators nowadays as well when they try to regulate against, uh, or regulate software security and sort of cyber security levels about what makes sense. And, uh, yeah, occasionally I get to talk to cool people like you.
I appreciate it. Well, not only that, but speaking of you and Brian, you guys have recently launched your own video series that we're carrying here on Text Drunk tv. So, you know, full disclosure, here's a cheap plug for a text drunk TV video series.
But give us, give us 30 seconds about what that's about. Hey, I'm really excited actually, that you guys took that on. So it's called From The Source, and it's all about, uh, me and Brian kind of picking a topic that's sort of coming up, uh, in those sort of world of supply chain.
We, we live and breathe this world. We, you know, Brian's a co-founder of Maven. Uh, I've been, you know, working with dozens and dozens and dozens of organizations for, actually, I did the math the other day, over 39 countries, uh, you know, kind of implementing supply chain security, et cetera.
So we kind of deep dive into kind of both, uh, the week's news about what's happening in this world of supply chain, like there's a new vulnerability or things like that. But we also kind of deep dive into a topic. So we just did one, um, uh, on ai.
We are doing a bunch of them on, uh, sort of various elements that you, uh, kind of see spoken about at DevSecOps World. So, uh, so yeah, so far it's been great doing that, actually Love it. Um, and of course you can get that on Techstrong tv.
You could look it up, it'll play, it plays on the Tech strong TV daily shows when it's, when the new episodes are out. And I think within the next couple days, it'll be available on all your favorite podcast channels, if it's not already Apple Podcast, Spotify, et. com, not Security Boulevard.
Um, though it can go in either one. I mean, 'cause it, you know, it straddles both worlds. Anyway, big news from Sona Type is, I believe it's October 10th, That's correct.
Is The annual A DDO all day DevOps event. This is the, the granddaddy of, of DevOps events was also probably the first big virtual event that we score, not just in DevOps, but maybe period. I mean, man, would the idea, when you guys first launched this, and I, we were, again, full disclosure, we were a sponsor back then of the first couple all day DevOps, um, 24 hours following the Sun, right?
People from all over the world, I think over a hundred speakers was, was usually the, the, uh, the play on it. What a, what a, an amazing, amazing concept. And it's still amazing.
It's coming up October 10th, I stole your thunder there. Oh girl. Sorry.
No, you, you guys did, but that I could not use better words for it. I'm really excited every year, uh, for all that ELs for a couple of reasons exactly that it follows the sun. So we started at 8:00 AM here in the uk.
Uh, we got folks standing by and production roll start. There's serious speakers throughout the day. So there's over a hundred speakers, uh, over four tracks, various different sort of topics related to all aspects of DevOps.
And it truly is all day. It runs for 24 hours from, uh, Don to dusk. We have got speakers in there from the uk, from Europe, from India, from uh, Asia.
We've got folks, uh, all across the Americas, uh, everybody dialing in. And what's really cool about a DDO is, um, is that you always learn something completely new. So this year, obviously there's a heavy focus in ai.
There's a heavy focus on sort of maybe the less spoken about aspects, uh, of DevOps, but also DevOps is so sort, kind of feels weird to say DevOps is over 10 years old too, as a concept, uh, even older. But it keeps evolving, keeps moving into this new direction, thanks to a bunch of this new technology kind of rolling out in the field. So what I really like about it is it's sort of the amalgamation of all the different sort of DevOps conferences that you see, you know, DevOps days, et cetera, and really kind of collects all the best material together and in a nice streamable format.
Absolutely. You know, we just released over it from our tech strong research division, what we're calling DevOps next. First time we've done this.
And it really looks at DevOps, what's next in DevOps, right? Where are we in DevOps, where are we on this journey? And it, it's, I've written a couple of articles.
com, but you know, when we, when I think of sonotype and I think of all the DevOps, I think about your annual, not on personally, but so do types annual report and that will be released or results will be released right from the, the quote unquote stage of A DDO this year, correct? That's, that's absolutely correct. So, um, uh, the next, uh, 10th annual edition of the status of the software supply chain report, which is one of these, one of these reports that we started doing because we wanted people to understand sort of the, the weird and granite numbers that we were seeing running Maven Central.
You know, one of those things that we do for the ecosystem we operate, one of the world's major opens with ecosystems. And we kind of kept running into these interesting tidbits, uh, of stuff like, Hey, people don want water vulnerable, open source components is more than you think. Um, and so we've been doing that report for 10 years.
It's kind of become a cornerstone, um, at least, um, sort of in the realm of security, open source management. It kind of describes how the world is consuming open source, what sort of risks are associated with it, but also about best practice. So this year we're particularly excited because, uh, what we've done is we we're taking a 10 year walk back at, uh, sort of all the sort of aggregated results and really asking that question.
So have we actually changed as an industry? Has something, uh, got different? And, you know, throughout the day, uh, in all day DevOps, we'll kind of touch on different sections of the report.
Uh, I'm gonna kick off the day, talk a little bit about the malware element, which is, uh, sort of an important part of it. Uh, and then throughout the day we'll look at all the other things like risk in open source, the scale of open source, uh, and other elements. Love it.
Um, I'm, and I'm looking forward to it. com. So this report, I mean, over the years, I can't tell you how many times we've quoted the report and kind of built themes around it.
You know, when you think back over the 10 years and there were a lot of, there's a lot of water under that bridge, right? The, the whole Equifax, uh, oh, struts, remember struts too. Yeah.
That's some of the work. Classic, Yeah. Some of the work in the report on that is still stuff I talk about.
Anyway, speaking of talking iki, you're, you're presenting at all day DevOps, and I think I, I have we kind enough here to get, uh, from hugging face to stack overflow open source attackers latest targets. Oh, no, that's not yours. That's one of the other highlighter, uh, mines, Uh, mine's, um, uh, malware in open source, the hidden threat, um, uh, hidden threat to your code, um, uh, sabotaging your software.
Uh, it's called the invisible threat. Invisible, right? So in fact, uh, I get the rare privilege of actually kicking off a DD.
It's the very first talk that we're giving. Wow. Good for you.
Congratulations. Well, you, no pressure, but, you know, No, no pressure. You'll be fine.
Look, it's eight o'clock in the morning by you, but it's probably eight o'clock or nine o'clock at night in Bangalore or something. So, you know, it's okay. You gotta keep those people up.
That, that's it, that's it. It's well past five o'clock somewhere, I'm sure. Uhhuh.
So now some of, some of what you're gonna be talking about here is pulled from the, uh, state of software supply chain report. Yes, sir. So what we're gonna do actually in this talk is, uh, kind deep dive into the malware portion of the report so I can, you know, if you promise to keep a secret between us and, uh, you know, Just as no one else is watching Us and, uh, these thousands of viewers, um, one of the kind of interesting things is, you know, over the years we've published this number.
So, you know, one of the things that we look at in the software supply chain is the prevalence of malware disguised as open source being published into open source ecosystem, sort of targeting developers. And every year the numbers sort of befalled us 'cause the number keeps growing. So, um, we've, uh, we keep seeing this, uh, sort of, uh, aggressive increase in sort of istic graph when it comes to the prevalence of this sort of malware.
Um, you know, last year, uh, I can, I can reveal that, uh, the growth rate is well over 156%, uh, year Wow. Is a very old credit business. Yeah, no, it's, it's been a hard year for software supply and, and, and now we're being put into the supply chain.
I mean, it's, you know, it's the world we live in, right? Uh, It is. And you know, one, one thing I'd like to say about that actually sure is, uh, is, um, not only is it the world that we are living in, but the serious professionals have also logged in, uh, on the turf.
So it's less sort of innocent ransomware that's nondescript, and it's much more serious malware that's being actually published by probably well backed actors, which has some consequences when we are, when we talk about making choices about open source, how do we defend ourselves against it? So there's, there's some interesting and sort of chilling facts, uh, about that. And I think, uh, I think it's something that certainly we should all be aware of, uh, not afraid of for sure, but aware of so that we can, uh, well, You can't live in your fears.
But look, the idea of sort of, you know, deep, deep teams that attributes to open source for years before they contribute something that contains malware, the idea of nation states, in addition to your, uh, presentation there would, I wanted to highlight three other ones. One I hit by accident earlier, which was from hugging face to stack overflow, open source, open source attackers, latest targets, which kind of dovetails a little bit with by what you're talking about, will developers become extinct? I talk about this all the time.
I think we're gonna go from 28 or whatever million developers in the world right now, thanks to ai. We're gonna have a 500 million developers in 10 years. They may not be the developers you're looking for, right?
But anyone can tell AI to write me on an app that does this, and that makes me a developer. And so I, I, I'd be interested in that session. And the third one I wanted to highlight was a keynote.
And that is the hidden trillion dollar engine of innovation. And for all those people out there, and they, you know, there might be someone out there who won. They will be the world's first trillionaire.
Uh, maybe you wanna pay attention to that. Finally, don't miss all day DevOps. It's a real easy place to go register.
com, right? That's correct. Go there, put your name down.
Super easy to get involved, and you'll get a link to the streams. Uh, and they're like, like the name says it runs all day. So let me, and so I'm not sure how it's running this year.
So if you're kicking off at eight o'clock London time, I'm on New York time, that's pretty early. That's like three in the morning for me and my with, if I log on at eight, can I just get you on demand or I gotta wait for the thing to play through, uh, As, as they kind of roll through, you can go through the agenda to see the session on demand and I'll really, I the organized Fantastic. Good stuff.
I wouldn't expect anything less of soda type team on all day DevOps, that's the way it should work. El I wanna thank you for jumping on. Hey man, I know you're gonna knock it out of the park on, on the 10th.
Congratulations on that. Congratulations to the whole soda type team on, on this 10th annual report. Looking forward to that.
com. Thanks so much for having me. Looking forward to it.
All Right, elker, and I'm gonna try to say this right, 'cause I said it right the first time. Elker, Turin, finish names, finish names. Sometimes they talk for me.
But we do the best we can and then be well. And good luck all day. DevOps, October 10th.
Don't miss it all day. com. We're gonna take a break here on Techstrong.
We'll be back in a minute.