# Open Source Community Secures CI/CD Pipelines in Luxembourg

Two major open-source software supply chain attacks targeting critical CI/CD pipeline packages have underscored significant cybersecurity risks for enterprises and public sector organizations, particularly within Luxembourg's regulated financial sector. At the Open Source Conference Luxembourg, the AsyncAPI Initiative presented detailed defense strategies including OIDC Trusted Publishing, automated CI/CD security scanning, hardened token isolation, least-privilege automation permissions, and continuous workflow auditing to mitigate these risks.

- Procurement professionals should prioritize vendors and solutions that incorporate advanced supply chain security measures such as OIDC Trusted Publishing and automated scanning to protect software development pipelines.
- Government agencies and contractors operating in regulated environments like Luxembourg's financial sector must evaluate their CI/CD security posture to comply with emerging best practices and reduce vulnerability to supply chain attacks.
- Organizations can leverage open-source community expertise, exemplified by AsyncAPI Initiative, to enhance pipeline security and integrate least-privilege automation controls.
- This development signals increased demand for secure software supply chain tools and services, creating procurement opportunities in cybersecurity and DevSecOps solutions tailored to CI/CD environments.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 15, 2026

### Vendors
- AsyncAPI Initiative (open source project and package maintainer)

### Key Quotes
> We will showcase how we overhauled our release pipelines using OIDC Trusted Publishing, automated CI/CD security scanning, hardened token isolation, least-privilege permission scopes on automation bots, and continuous workflow auditing.
> — Florence Njeri, Cybersecurity Engineer

### Sources
- [
            Securing Open Source CI/CD  Pipelines: Lessons from Handling 2 Supply Chain Incidents ::
            
                Open Source Conference Luxembourg
            :: pretalx
        ](https://pretalx.com/open-source-conference-luxembourg-2026/talk/ETANAX) - Pretalx