35 Million Lines, Zero Build-Breakers:
How Adyen Scaled DevSecOps

March 31st, 2026 | 10:00 AM CET

 

March 31st, 2026

10:00 AM CET

 

When managing a massive, multi-language monolith with over 35 million lines of code, visibility is the first casualty. For Adyen, the challenge wasn’t just finding vulnerabilities, but identifying dependencies at all within a highly customized build environment.


In this technical session, Adyen DevSecOps Specialist Supun Vidana Pathiranage and JFrog’s Yonatan Arbel break down the architecture Adyen built to decouple dependency resolution from their core build system. This approach enables accurate, scalable visibility and reliable security scanning without disrupting developer workflows or requiring a total system rewrite.


In this session, you’ll learn:

  • Architectural patterns for managing dependency visibility in massive, multi-language monorepos without rewriting your build system
  • How Adyen integrated a custom-built pipeline with JFrog Xray, including the constraints, compromises, and design decisions that made deep SCA scanning possible
  • The Battlestar framework: how Adyen turns raw scan results into actionable security feedback that developers can act on
  • Shift-left AppSec enforcement in practice: implementing security gates at the Merge Request level without slowing down delivery or drowning teams in false positives

You’ll leave with concrete patterns for modernizing your software supply chain, enforcing meaningful security gates, and scaling DevSecOps across complex, real-world build environments.

 

Presenter Information

 
 
 

Supun Vidana Pathiranage

DevSecOps Specialist, Adyen

 

Supun Vidana Pathiranage | DevSecOps Specialist, Adyen

 

Supun specializes in securing large-scale, multi-language ecosystems. He led the architectural shift at Adyen to decouple dependency resolution from core build processes, enabling deep security scanning for one of the world’s largest financial monoliths.

 
 

Yonatan Arbel

Developer Advocacy Lead, JFrog 

 

Yonatan Arbel | Developer Advocacy Lead, JFrog 

 

Yonatan works at the intersection of developer velocity and binary security. He focuses on helping enterprises transform raw security signals into automated, trustworthy enforcement policies using the JFrog Platform.

 
 
 
 
 
 
JFrog Facebook
 
 
YouTube
 
 
JFrog LinkedIn
 
 
JFrog Twitter
 

Terms of Use | Privacy Notice | Read Our Blog | Start for Free | Contact Us

 

© 2026 Copyright JFrog Inc. All rights reserved.

 

© 2026 Copyright JFrog Inc

All rights reserved.

Terms of Use

Privacy Notice

Read Our Blog

Start for Free

Contact Us