
Justin Cormack on Integrating Security into Software Building
About this episode
In this episode of Semaphore Uncut, Justin Cormack, Senior Security Engineer at Docker and member of the Technical Oversight Committee at CNCF, shares insights from the security industry. We talk about why it’s important to think about what could go wrong when building software, how hackers are now exploiting vulnerabilities before shipping your code to production, and what companies can really do and use to secure their products.
Key takeaways:
- Security – a matter of software quality
- The threat modeling practice – understanding the potential security threats
- Using the experience of experts
- Supply-chain security
- Security integration into CI/CD pipelines
- Important vs. overhyped practices in the security industry
About Semaphore Uncut
In each episode of Semaphore Uncut, we invite software industry professionals to discuss the impact they are making and what excites them about the emerging technologies.
This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit semaphoreio.substack.com
Get every episode summarized
Each time Semaphore Uncut publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Semaphore Uncut

New: OAuth for MCP Servers — Lessons from Building for AI Agents
Semaphore Uncut

Semaphore’s New Pricing Model: Built for the AI Era of CICD
Semaphore Uncut

Product News: OAuth Authentication for the Semaphore MCP Server
Semaphore Uncut

Product Update: AI-Driven Onboarding and Workflow Automation in Semaphore
Semaphore Uncut