Secure development goes beyond plugins in SonarQube.

mansplainer
João Brito

Security in Go is not just about "running a scanner and praying." In this episode, we break down how to write Go with an attacker's mindset: dependency governance (and the dangers of type-squatting), reviewing go.mod, judicious use of the Standard Library, and why you should not use latest in images. We also connect technology with process: private repositories, approval policies, and pipelines that block regressions before deployment.
The conversation stems from real cases: from the typo in (GHCR vs GHRC) that captures credentials to the confusion with fake packages like BoltDB look-alikes. We discuss end-to-end supply chain, Go Proxy cache, licenses (when to avoid GPL), and best practices for authentication.
And of course, we go beyond the code: SBOM in builds, image signing and verification, OPA/Admission Control for Kubernetes policies, minimum capabilities, and input validation with well-defined timeouts. It's practical talk, with our usual humor, to make security the default — not a last-minute chore.
Important Links:
- Marcelo Pires - https://www.linkedin.com/in/marcpires/
- Matheus Faria - https://www.linkedin.com/in/matheusfm/
- João Brito - https://www.linkedin.com/in/juniorjbn
- Watch the Movie TEArapia - https://youtu.be/M4QFmW_HZh0?si=HIXBDWZJ8yPbpflM -
Post about ghrc.io - https://www.linkedin.com/posts/juniorjbn_someone-is-typosquatting-ghrcio-not-github-activity-7364387040618045441-UB88/
- Typosquat - https://devops.com/typosquat-supply-chain-attack-targets-go-developers/
- https://go.dev/doc/tutorial/govulncheck
- vuln.go.dev
- https://github.com/anchore/syft
- https://github.com/anchore/grype
- https://github.com/google/capslock
- https://github.com/aquasecurity/trivy
- LFD121 - https://training.linuxfoundation.org/training/developing-secure-software-lfd121/
- https://deps.dev/
- https://devops.com/typosquat-supply-chain-attack-targets-go-developers/
Join our early access program and have a more secure environment in moments! https://getup.io/zerocve
🎧 Also listen to Kubicast on Spotify, and share it with everyone in development who needs to know a bit more about the topic!
Newsletter Getup.
Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.
Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.
GET UP
© Getup · 2026

