BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.devopsdays.org//halifax-2026//talk//98ZJQE
BEGIN:VTIMEZONE
TZID:America/Halifax
BEGIN:DAYLIGHT
DTSTART:20250929T000000
TZNAME:ADT
TZOFFSETFROM:-0300
TZOFFSETTO:-0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251102T020000
RDATE:20261101T020000
TZNAME:AST
TZOFFSETFROM:-0300
TZOFFSETTO:-0400
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260308T030000
RDATE:20270314T030000
TZNAME:ADT
TZOFFSETFROM:-0400
TZOFFSETTO:-0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:The Audit-Proof Way to Ignore a CVE - Charl Cilliers
DTSTART;TZID=America/Halifax:20260929T143000
DTEND;TZID=America/Halifax:20260929T150000
DTSTAMP:20260922T232232Z
UID:pretalx-halifax-2026-98ZJQE@talks.devopsdays.org
DESCRIPTION:Your scanner found multiple vulnerabilities in your base image
  this morning\, and your release is blocked until every one of them is tri
 aged out of the queue. Most of them will never be fixed\, and for most of 
 them that is the correct outcome. \n\nThe catch: you work on government co
 de\, so you can't hand the problem to the tools built to solve it. \n\nThe
  agentic CVE-analysis platforms want to embed your source. The good commer
 cial suites cost real money and still phone home. And the rules about AI a
 nd sensitive code are only getting tighter. \n\nSo this talk is about a qu
 estion I had to actually answer on a live government program: how do you s
 upercharge vulnerability triage using the most powerful tools available\, 
 without a single byte of privileged code or infrastructure leaving your bo
 undary?
LOCATION:Volta HQ
URL:https://talks.devopsdays.org/halifax-2026/talk/98ZJQE/
END:VEVENT
END:VCALENDAR
