Open Source DevSecOps Contributor
Mar 2026 – PresentEBRAINS / Medical Informatics Platform ↗
Google Summer of Code 2026 ↗ under INCF, May – Oct 2026. Selected as 1 of 1,141 contributors from 15,245 applicants (7.5%).
EBRAINS is Europe's digital research infrastructure for neuroscience. Its Medical Informatics Platform lets hospitals analyze harmonized clinical data without moving patient records off local servers. I started contributing before GSoC, was selected to secure the platform's CI/CD supply chain against the OWASP DevSecOps Maturity Model, ahead of the EU Cyber Resilience Act and NIS2, and keep contributing beyond the program.
- Assessed the platform against OWASP DSOMM and turned the gaps into an implementation roadmap.
- Shipped SAST (OpenGrep), SBOM-based SCA (Trivy and OSV-Scanner over CycloneDX SBOMs) and container scanning (Hadolint, Trivy, OSV-Scanner) into the Spring Boot backend, the Angular UI and the data catalog, where one build matrix covers Maven, npm and Python services.
- Added Gitleaks secret scanning in pre-commit hooks and CI.
- Designed one fail-closed security gate: every scanner is normalized to SARIF, builds are blocked at CVSS 8.0 or on ERROR-level SAST rules, a crashed scanner never counts as a pass, and reports are GPG-encrypted before upload because findings in a public repository are sensitive.
- Secured the pipelines themselves: GitHub Actions pinned to commit SHAs, Renovate and Dependabot with a 7-day cooldown, and containers running as non-root.
- Packaged the work as a reusable blueprint and the EBRAINS DevSecOps Handbook, and upstreamed the gate design to the OWASP DevSecOps Guideline.
- Now hardening the Kubernetes GitOps repository (Argo CD, HAProxy ingress) so Checkov IaC scanning can become a blocking gate.
13 merged PRs platform-backend #15 #19 #23 #25 · platform-ui #20 #23 #27 #31 #34 #38 · datacatalog #18 · mip-infra #2 #6