Authors

Tim Bastin

Tim Bastin

CTO & Software Security Specialist

Tim Bastin is passionate about getting the most out of every line of code. As CTO of L3montree Cybersecurity, an experienced software architect, and a software security specialist, he combines deep technical expertise with a clear mission: high-quality, secure code preferably 100% open source. His professional foundation is built on a bachelor’s degree in computer science with a focus on complex software systems, as well as a master’s degree in computer science. At L3montree, he aims to make IT security practical and effective for businesses through a pragmatic approach, without compromising on quality or security. Tim is a big fan of open source and, as a maintainer, actively contributes to the community to make the software landscape safer overall. His commitment extends beyond pure development: As a member of the Technical Advisory Board for the Container.gov.de initiative, he contributes his expertise to the creation of secure and digitally sovereign software infrastructures for Europe. In addition, he is a regular speaker at conferences such as FrOSCon, the BSI’s CSAF Community Days, heise DevSecOps, and OWASP.

Articles by Tim Bastin

Tim Bastin
Vulnerability Management · 13 Aug 2026

DevGuard Vulnerability Database and the EUVD

When it comes to Vulnerability Management Tools, having a good vulnerability database is crucial. While it seems simple to just synchronize CVEs from a source like the NVD and call it a day, but building a good vulnerability database is far more nuanced than that. Here's what sources DevGuard synchronizes and why, how the VulnDB pipeline actually operates, and how we approached synchronizing the EUVD's sources.

Tim Bastin
17 min read

Publications by Tim Bastin

Tim Bastin
Apr 2026 · EN

Bit-for-Bit: How we built a sovereign, reproducible container supply chain for DevGuard

This paper presents how the DevGuard project rebuilt its OCI container supply chain around reproducible Nix builds and independent dual-platform digest verification to reduce trust assumptions in modern software delivery. By combining hermetic builds, Sigstore attestations, and digest comparison across GitHub Actions and sovereign GitLab infrastructure on container.gov.de, the approach provides a practically verifiable integrity guarantee against build tampering beyond provenance alone.

Author: Tim Bastin
PDF download