From CVD to Secure Releases: Automating Security from Source to Releases @FIRSTdotorg
From CVD to Secure Releases: Automating Security from Source to Releases  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 5 hours ago
Vijay Sarvepalli (Software Engineering Institute, US), Christopher Cullen (CMU Software Engineering Institute, US)

As open‑source ecosystems grow ever more central to modern software development, the traditional view of Coordinated Vulnerability Disclosure (CVD) as a “nice‑to‑have” becomes dangerously inadequate. In this talk — “Beyond CVD: Automating Software Security from Source Code to Release” — I argue that CVD must evolve: not just to notify, but to actively secure software supply chains, builds, releases, and audit tools. By integrating CVD into developer workflows on platforms such as GitHub, GitLab, and public registries like npm and PyPI, we can shift security “left,” enforce continuous policy checks, and ensure that disclosure actually leads to safer software in production.

---

Vijay Sarvepalli works as Principal Engineer at CERT division of Carnegie Mellon University Software Engineering Institute. Vijay is a seasoned professional with extensive expertise in software architecture, cybersecurity, and enterprise systems. Vijay has a broad background in software architecture, solutions architecture and enterprise architecture. Vijay is TOGAF 9 Enterprise Architect Practitioner with specialized skills in developing strategy, innovation with a focus on closing the gap between strategy and execution. In his previous roles, he has broad experience in multiple vertical industries with roles such as Practice Head for Innovations, Technical Lead for Managed Services and IT Architect for Campus Information Services. Vijay has BS and MS degrees in Electrical and Computer Engineering and a MIT Executive Certificate in Strategy and Innovations.

Christopher Cullen is a Vulnerability Researcher involved in research within the fields of malware, threat intelligence, vulnerabilities, and AI/ML. During his time at the SEI he has advanced the team mission through numerous partner engagements, including with CISA, the NSA, and OT&E. His previous experience includes working for the NCFTA as a Malware Analyst, where he was the lead forensic examiner and involved in analysis projects for government entities and Fortune 500 companies involving malware, vulnerability, and forensic analysis.

Chris works with CISA in the realm of vulnerability coordination, having published vulnerability notes and coordinated several cases with over 100 vendors, introduced patches, and worked to further reduce system vulnerabilities. For malware, he supports red team assessments and provides technical reporting that guides development. He has provided research regarding systemic issues and problems that our government partners need to be aware of in regard to AI and ML to prevent harm. His other involvement includes representing the SEI in conferences, panels, and other public facing interview capacities.
From CVD to Secure Releases: Automating Security from Source to ReleasesOnly Seeing Stars: Enabling the Open Source Scripting Community with OCSFInside the Information Stealer Ecosystem: From Compromise to CountermeasureImproving Security Across Nations with FIRST: Tom Millar, FIRST TLP SIG Co-chairDraugnet: Anonymous Threat Reporting That Actually WorksAutomated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New MalwareAI Interpretability as a Security Control: Introducing the CIRCUIT FrameworkFrom Dork to Diplomat: Communicating Coherently for Vulnerability & Incident ResponseBroken Seals, Broken Trust: Flaws and Defences in the Certificate Ecosystem
FIRST |

From CVD to Secure Releases: Automating Security from Source to Releases

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER