Billy Lynch is a Principal Software Engineer with 13 years of experience building and securing cloud-native CI/CD and supply-chain tooling, currently based in New York and leading engineering at Chainguard. He brings deep backend and DevOps expertise from Google and prominent open-source projects—contributions to TektonCD, Sigstore/cosign, and go-github demonstrate hands-on improvements to build automation, code signing, and API robustness. Billy blends systems design with practical toolsmithing: refactoring context propagation, improving test and dependency hygiene, and adding credential caching and OIDC integrations to real-world security tooling. As a TektonCD governing board member and frequent maintainer, he pairs governance with code-level ownership, often tackling subtle interoperability and configuration issues that improve developer experience and security posture. Notably, his work includes enhancing supply-chain security primitives used by many cloud-native projects, reflecting a focus on auditable, reproducible pipelines.
13 years of coding experience
14 years of employment as a software developer
Bachelor of Science (BS) Computer Science, Bachelor of Science (BS) Computer Science at Rutgers University
Contributions:5 releases, 140 reviews, 89 commits in 9 months
Contributions summary:Billy primarily contributed to the `sigstore/gitsign` repository by cleaning up code and introducing new features. Their work involved enabling OIDC providers, filtering Rekor search by public key, and enabling file-based configuration. They also implemented a credential caching system to improve efficiency. Furthermore, the user refactored sign/verify processes and enhanced verification output.
A lightweight tool to report on the licenses used by a Go package and its dependencies. Highlight! Versioned external URL to licenses can be found at the same time.
Role in this project:
Back-end Developer
Contributions:1 release, 60 reviews, 7 commits in 2 years 2 months
Contributions summary:Billy primarily contributed to the `go-licenses` project by implementing new functionalities and refining existing ones. They added a "check" command for license verification and enhanced command-line argument handling to accept multiple input paths. Furthermore, the user addressed a spelling inconsistency ("LICENCE") in a test, and fixed file permissions when saving license information. These changes demonstrate a focus on improving the tool's usability, robustness, and adherence to best practices.
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.