As the Chief Information Security Officer at the Erlang Ecosystem Foundation (EEF), Jonatan drives security initiatives across Erlang, Elixir, Gleam, and the broader community. His role involves analyzing and implementing data protection, compliance, and secure development practices—particularly focusing on requirements like EU CRA/CISA and supply chain integrity. He maintains the EEF’s CNA (CVE Numbering Authority), ensuring vulnerability disclosures are managed effectively. He also collaborates closely with volunteer working groups, designs software solutions for security challenges, and actively engages in fundraising activities.
Every Elixir developer uses the Hex package manager to ship their project. Businesses, universities, and even governments all rely on this critical infrastructure to adopt Elixir and deliver high quality software that drives billions of dollars in economic activity and growth. Given Hex is a load bearing pillar of Elixir, have you ever asked yourself: Is it secure?
Thanks to the Ægis Initiative, two real world penetration tests of Hex were funded, successfully completed, and directly resulted in serious security vulnerabilities being blocked from release. This work confirmed the design decisions made by the Hex core team laid an incredibly secure foundation, and led to improvements that have made Hex more secure than ever before. This presentation will cover the results of both tests (which are public for full transparency), and the remediation efforts that prove the core infrastructure of Elixir is safe in the hands of a world class team.
Key takeaways:
Target audience: