Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378

Application Security Weekly (Audio)1h 9mApril 14, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378” inside PodZeus.

AI-Generated Summary

This episode of Application Security Weekly dives deep into the OWASP Secure Pipeline Verification Standard (SPVS), a new framework co-created by Farshad Abassi and Cameron Walters to address the growing security risks in CI/CD pipelines. The conversation explores why SPVS was needed beyond existing standards like the OWASP Top 10, emphasizing its broad scope—from code inception to deployment—and its focus on modern threats like AI-driven development and supply chain attacks. The guests highlight how SPVS introduces maturity levels, community-driven feedback, and AI-specific controls to tackle agentic engineering, AI bombs, and unpredictable AI behavior. They also discuss real-world applicability, using the Axios/NPM breach as a case study, and stress the importance of 'upgrade with intent' over passive cooldowns. Later segments feature Rohan Ravindranath on Zero Trust as Code, advocating for embedding security policies into infrastructure pipelines with automated drift detection, and Ido Geffen of Novi Security, who presents an AI-powered penetration testing platform that goes beyond vulnerability scanning by offering exploitability validation, full transparency, and custom remediation guidance—especially for business logic flaws and AI components.

Key Takeaways
1

SPVS is not just another Top 10—it’s a maturity-based, community-driven standard covering the entire software delivery lifecycle, from planning to operation.

2

AI-specific controls in SPVS address unique risks like agentic engineering, AI bombs, and unpredictable behavior, which traditional scripts can’t capture.

3

Security must be embedded early (shift-left) and codified as 'Zero Trust as Code' to avoid the 'gate at the end' problem and ensure consistent enforcement.

4

AI-powered pen testing should go beyond scanning: true exploitability validation, full transparency, and business logic-aware remediation are critical differentiators.

5

The 'upgrade with intent' principle replaces passive package cooldowns with proactive, risk-informed updates to reduce supply chain exposure.

Chapters
0:00
10 min

Introducing the OWASP SPVS: Why a New Standard?

We thought something like ASVS for pipelines would be a great idea.

Highlight
10:00
15 min

Scope and Structure: From Code Inception to Operation

The guests clarify that SPVS extends beyond CI/CD to include the entire SDLC—from planning and policy to operating and monitoring. They emphasize the importance of policy in the 'plan' stage and how controls are grouped by SDLC phases to improve usability and reduce overwhelm.

25:00
17 min

AI and the Future of Pipeline Security

AI is neither a service nor a human. It can do unpredictable things kind of like a human, but it is not a human. So it warrants its own type of identity and its own type of security controls.

Highlight
41:40
17 min

Learning from Real Breaches: The Axios/NPM Case

I found a couple different gaps. So do expect that there'll be a quick follow-up. That's what I'm actively working on right now...

Highlight
58:20
17 min

Zero Trust as Code: From Strategy to Reality

The foundational idea of zero-trust-as-code is really simple, which is that your security policies shouldn't be treated any differently than your infrastructure code.

Highlight
High-Impact Quotes
AI is neither a service nor a human. It can do unpredictable things kind of like a human, but it is not a human. So it warrants its own type of identity and its own type of security controls.
Farshad Abassi27:17
Viral: 90.0
We are not stopping there right away. I mean, yeah, it is exploitable, but now what can you do with that? So give it the right level of utilization...
Ido Geffen62:54
Viral: 88.0
We thought something like ASVS for pipelines would be a great idea.
Cameron Walters4:33
Viral: 85.0
Speakers

Hosts

Mike ShimaJohn Kinsella

Guests

Farshad AbassiCameron WaltersRohan RavindranathIdo Geffen
Topics Discussed
secure pipeline verification standard95%ai security in ci-cd90%zero trust as code88%ai pen testing87%supply chain security85%agentic engineering82%business logic vulnerabilities80%drift detection78%
People & Brands

Cameron Walters

person

22xPositive

Farshad Abassi

person

18xPositive

OWASP

organization

15xPositive

SPVS

other

14xPositive

Rohan Ravindranath

person

10xPositive

Ido Geffen

person

8xPositive

Novi Security

organization

7xPositive

ZAPSEC

organization

6xPositive

RSAC 2026

other

5xPositive

SBOM

other

4xMixed

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “Securing Software's Journey with the OWASP SPVS - Ido Geffen, Rohan Ravindranath, Cameron W., Farshad Abasi - ASW #378” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime