35 Million Lines, Zero Build-Breakers:
How Adyen Scaled DevSecOps
When managing a massive, multi-language monolith with over 35 million lines of code, visibility is the first casualty. For Adyen, the challenge wasn’t just finding vulnerabilities, but identifying dependencies at all within a highly customized build environment.
In this technical session, Adyen DevSecOps Specialist Supun Vidana Pathiranage and JFrog’s Yonatan Arbel break down the architecture Adyen built to decouple dependency resolution from their core build system. This approach enables accurate, scalable visibility and reliable security scanning without disrupting developer workflows or requiring a total system rewrite.
In this session, you’ll learn:
You’ll leave with concrete patterns for modernizing your software supply chain, enforcing meaningful security gates, and scaling DevSecOps across complex, real-world build environments.
Presenter Information

Supun specializes in securing large-scale, multi-language ecosystems. He led the architectural shift at Adyen to decouple dependency resolution from core build processes, enabling deep security scanning for one of the world’s largest financial monoliths.

Yonatan works at the intersection of developer velocity and binary security. He focuses on helping enterprises transform raw security signals into automated, trustworthy enforcement policies using the JFrog Platform.