Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Vulnerability Response for Large Open Source Projects - Jo Guerreiro & Charline Voinot, Grafana Labs
Vulnerability management is an evolving topic that was hard pre-coding agents and can now become overwhelming for security and authentication teams. Add to that multi-version support, multi-tenancy and separate deployment waves and you have the recipe for an unmitigated headache.
Join Grafana’s journey in this topic as we deep dive into how we handled CVE-2023-3128 three years ago and how we handle vulnerability classification and patch distribution, from our cloud environment to millions of Grafana instances worldwide, today.
You’ll learn how to distinguish between a vulnerability and an intended feature, how to orchestrate the rollout of a vulnerability patch and how to remain transparent to your community of users without placing their deployments at risk. When maintainers face increasing pressure from a high volume of pull requests and AI-generated vulnerability reports, there is a critical need to refine and advance our security practices.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Vulnerability Response for Large Open Source Projects - Jo Guerreiro & Charline Voinot, Grafana Labs
Vulnerability management is an evolving topic that was hard pre-coding agents and can now become overwhelming for security and authentication teams. Add to that multi-version support, multi-tenancy and separate deployment waves and you have the recipe for an unmitigated headache.
Join Grafana’s journey in this topic as we deep dive into how we handled CVE-2023-3128 three years ago and how we handle vulnerability classification and patch distribution, from our cloud environment to millions of Grafana instances worldwide, today.
You’ll learn how to distinguish between a vulnerability and an intended feature, how to orchestrate the rollout of a vulnerability patch and how to remain transparent to your community of users without placing their deployments at risk. When maintainers face increasing pressure from a high volume of pull requests and AI-generated vulnerability reports, there is a critical need to refine and advance our security practices.










