
Episode #9
Build from source with Matt Moore from Chainguard | Zero-Shot Learning
In 2020, the SolarWinds attack exposed the vulnerability of supply chains worldwide, a problem this episode’s guest, Matt Moore, had already been working to solve for years. In 2021, he co-founded Chainguard to protect supply chains from future breaches. His conversation with 1Password CTO Nancy Wang and Google Gemini’s Dev Tagare covers why the open source trust model is structurally broken and how AI agents have complicated supply chain security, with a live demo demonstrating how standard tools overlook many vulnerabilities. In this episode: AI is shrinking the window for patching, as AI-powered attacks accelerate and demand for pre-alpha code grows Hacks usually target the delivery pipeline rather than the source code Net-new, AI agent-written code creates more burden for teams to maintain and secure Most breaches exploit long-lived credentials Audited least privilege flips the security model from restricting identities to guarding sensitive resources Zero-Shot Learning is a builder-to-builder podcast about how AI systems are designed, deployed, and secured. Subscribe for more. Go deeper: Episode companion blog: https://www.1password.com/blog/software-supply-chain-identity-security 1Password Developer newsletter: https://1password.com/developer-newsletter LinkedIn: https://www.linkedin.com/in/mattmoor/ Connect with 1Password 1Password.com 1Password Developer newsletter: https://1password.com/developer-newsletter Build securely with 1Password Developer: https://developer.1password.com/






