BEGIN:VCALENDAR
VERSION:2.0
X-WR-CALNAME:openssfcdeu2026
X-WR-CALDESC:Event Calendar
METHOD:PUBLISH
CALSCALE:GREGORIAN
PRODID:-//Sched.com OpenSSF Community Day Europe 2026//EN
X-WR-TIMEZONE:UTC
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T060000Z
DTEND:20261006T154000Z
SUMMARY:Registration + Badge Pick-up
DESCRIPTION:\n
CATEGORIES:BREAKS & REGISTRATION
LOCATION:Prague\, Czechia
SEQUENCE:0
UID:a3ed1a3573460b5a768f5ed08d35dc2e
URL:http://openssfcdeu2026.sched.com/event/a3ed1a3573460b5a768f5ed08d35dc2e
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T070000Z
DTEND:20261006T071000Z
SUMMARY:Keynote: Welcome & Opening Remarks - Steve Fernandez\, OpenSSF Managing Director\, The Linux Foundation
DESCRIPTION:\n
CATEGORIES:KEYNOTE SESSIONS
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:4b2de9120a38a076f54ed8aad80e98a4
URL:http://openssfcdeu2026.sched.com/event/4b2de9120a38a076f54ed8aad80e98a4
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T071000Z
DTEND:20261006T080000Z
SUMMARY:Keynote Sessions To Be Announced
DESCRIPTION:\n
CATEGORIES:KEYNOTE SESSIONS
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:cf774564f55365a0069a8b5593da6383
URL:http://openssfcdeu2026.sched.com/event/cf774564f55365a0069a8b5593da6383
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T080000Z
DTEND:20261006T083000Z
SUMMARY:Break
DESCRIPTION:\n
CATEGORIES:BREAKS & REGISTRATION
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:87b1835eb8182f8e633551a78cd6fce5
URL:http://openssfcdeu2026.sched.com/event/87b1835eb8182f8e633551a78cd6fce5
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T083000Z
DTEND:20261006T085000Z
SUMMARY:Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann\, iRights.Law Rechtsanwälte
DESCRIPTION:On 8 Sept 2025\, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk\, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone\, who pays? \n Two EU laws finalised in 2024 shape the answer\, the Product Liability Directive and the Cyber Resilience Act\, and their duties phase in across 2026 and 2027. So we go hands-on: we take this real compromise and walk it\, step by step\, down the liability chain. The maintainer\, it turns out\, is the one the law works hardest to shield as non-commercial open source sits largely outside both regimes. The bill lands downstream\, on the commercial manufacturer who ships debug inside a product. Under the PLD\, a missing security update can itself be a defect\, under strict liability. The CRA adds a second layer since it lays a duty on to manage exactly this kind of vulnerability - detect it\, report it\, patch it - backed by fines\, while the "open-source steward" carries a lighter\, fine-free load.
CATEGORIES:REGULATORY COMPLIANCE
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:88dd0b270fc698b61e132e08755a8ed4
URL:http://openssfcdeu2026.sched.com/event/88dd0b270fc698b61e132e08755a8ed4
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T085500Z
DTEND:20261006T091500Z
SUMMARY:Preparing for the Vulnpocalypse: Using OSS-CRS To Find and Fix Bugs Before They Find You - Jeff Diecks\, OpenSSF & Laura Guazzelli\, Linux Foundation
DESCRIPTION:The open source ecosystem faces a Vulnpocalypse as AI-driven vulnerability reports surge. While potentially beneficial for security long-term\, the current volume threatens to overwhelm open source projects. Maintainers work at human speed\, and each report requires careful attention\, verification\, and disclosure. \n \n So we need machines to help fix what the machines are finding. \n \n In this workshop.we will walk through OSS-CRS. It's an OpenSSF project that gives us a standard orchestration framework for Cyber Reasoning Systems (CRS) capable of finding\, proving and patching vulnerabilities. \n \n Beyond the technology\, we examine critical best practices for CRS usage. This includes how to build community norms that respect a maintainer's time instead of just dumping more work on their plate. \n \n Attendees will learn: \n - The current trends of AI-generated reports and the impact on open source \n - How to run OSS-CRS for bug finding and fixing. \n - Best practices for responsible use of AI tools in CVD.
CATEGORIES:AI AND ML IN SECURITY
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:8eb76b197b0db837e9f1d8d97a49757d
URL:http://openssfcdeu2026.sched.com/event/8eb76b197b0db837e9f1d8d97a49757d
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T092000Z
DTEND:20261006T094000Z
SUMMARY:Defending Bare-Metal: Lessons Learnt From AI Security Analysis of Metal3 and OpenStack Ironic - Dmitry Tantsur\, Red Hat & Tuomo Tanskanen\, Ericsson Software Technology
DESCRIPTION:AI-powered vulnerability discovery is here\, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However\, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze\, especially as low-hanging fruit is rapidly plucked. In this session\, maintainers and security team members from Metal3.io and OpenStack Ironic projects share how they used an AI-based vulnerability analysis tool to uncover hidden issues. This domain is often riddled with legacy drivers and requirements to support deprecated protocols\, yet built on modern cloud-native architectures where a vulnerability proof is rarely an easily automated\, executable crash. For project maintainers\, we will share our candid analysis of the typical AI report shortcomings\, what to look for in triage\, and how to deal with the incoming flow without burning out.
CATEGORIES:AI AND ML IN SECURITY
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:55a359572d8ddad10a59d10ea04bc7ef
URL:http://openssfcdeu2026.sched.com/event/55a359572d8ddad10a59d10ea04bc7ef
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T094500Z
DTEND:20261006T100000Z
SUMMARY:From First PR To Hardening Guide: Structured Security With Gemara - Hannah Braswell\, Red Hat
DESCRIPTION:We've all been new contributors at some point. You know the learning curve - best practices established before your first PR\, specs that have been evolving for years. Should PRs require 3 reviewers? Do I need MFA? What are the actual threats to this project? Contributors need a clear way to understand not just how to contribute\, but how to contribute securely. The OpenSSF Gemara Project provides a standardized model and tooling to help projects define capabilities\, identify threats\, and document the controls that prevent them\, structured across a 7-layer architecture. For maintainers shipping open source into the EU under the Cyber Resilience Act\, structured governance isn't optional.
CATEGORIES:ENHANCING SECURITY TOOLS
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:15cbc4b16f750f1b76909f2cf22975ce
URL:http://openssfcdeu2026.sched.com/event/15cbc4b16f750f1b76909f2cf22975ce
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T100500Z
DTEND:20261006T102000Z
SUMMARY:The SLSA Tooling Cake - Adolfo García Veytia\, Carabiner Systems
DESCRIPTION:Starting in 2025\, the SLSA project overhauled the tool catalog it maintains\, unveiling new libraries and utilities while sunsetting older repositories that were not maintained any longer. \n \n The project has now overhauled the projects under the SLSA umbrella into a more coherent stack starting with the spec and definitions at the bottom all the way to community integrations at the top. This is what we call the SLSA Tooling Cake and it is filled in the middle with delicious developer tools and end-user CLI tools. \n \n In this talk we'll go through each of the five layers of the cake understanding what each offers to different consumers types: tool designers\, agents\, developers\, end users\, integrators\, ecosystem partners\, etc \n \n During the talk we will also show a brief demo of each of the CLI tools: onboarding a repo to SLSA Source\, generating a build provenance attestation and verifying it with the new pluggable verifier. We will also see how the new conformance suite ensures the SLSA ecosystem produces compatible data.
CATEGORIES:SECURING THE SOFTWARE SUPPLY CHAIN
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:8e6d27af05b9c33b4b4dce1f306661e8
URL:http://openssfcdeu2026.sched.com/event/8e6d27af05b9c33b4b4dce1f306661e8
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T102500Z
DTEND:20261006T104000Z
SUMMARY:One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne\, AboutCode & Stephen Augustus\, Bloomberg
DESCRIPTION:Open source supply chain decisions such as what to depend on\, what to ship\, and what to trust are only as good as the open data behind them. The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million\, both with ScanCode. We share the same problem: we're scanning and rescanning the same packages for the same (or similar) data. That redundancy has real costs. Compute\, maintainer time\, and contributor energy spent on work that's already done is capacity not spent on expanding coverage\, improving accuracy\, or hardening infrastructure. It's time to build together. This talk is a conversation about what it would look like to join forces on open software supply chain data\, produced with open source tools and backed by open standards with shared infrastructure and aligned and unlocked datasets for wider usage. We'll explore where our data models overlap\, where they diverge\, and what collaboration would require\, so we all can get sustainable\, high-quality\, and open supply chain data at ecosystem scale faster together.
CATEGORIES:SECURING THE SOFTWARE SUPPLY CHAIN
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:f21eb4427332e74a79563cd024c1ed07
URL:http://openssfcdeu2026.sched.com/event/f21eb4427332e74a79563cd024c1ed07
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T104000Z
DTEND:20261006T115500Z
SUMMARY:Lunch
DESCRIPTION:\n
CATEGORIES:BREAKS & REGISTRATION
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:f27de48e97cbd0e2f12706dd5317e2bd
URL:http://openssfcdeu2026.sched.com/event/f27de48e97cbd0e2f12706dd5317e2bd
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T115500Z
DTEND:20261006T131000Z
SUMMARY:Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov\, Red Hat; Daniel Appelquist\, Samsung Electronics; Madalin Neag\, OpenSSF; Megan Knight\, Arm
DESCRIPTION:As of Sept 11\, 2026\, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet\, Linux Foundation research shows 66% of the ecosystem remains unprepared\, risking expensive "private forking" traps. \n \n Hosted by the OpenSSF Global Cyber Policy WG\, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities a lot of us are facing right now. Following a short briefing\, the core 1-hour session unites enterprise engineers\, security officers\, stewards\, open source developers and layers in collaborative 3 breakouts to stress-test real-world CRA challenges. Topics include: governance\, open source particularities and CRA personas across varying PDE classifications\, as well as secure-by-design mandates\, risk assessments\, due diligence\, SBOMs\, vulnerability management and reporting obligations. We conclude with a 15-minute synthesis of mapping live insights directly to OpenSSF roadmap and our work for the upcoming quarters. \n \n Whether you are an enterprise architect trying to keep your product compliant\, a steward\, or an upstream developer\, this workshop offers to tackle your specific use cases.
CATEGORIES:REGULATORY COMPLIANCE
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:402355d3edc7264f0e5bef740e37c4e2
URL:http://openssfcdeu2026.sched.com/event/402355d3edc7264f0e5bef740e37c4e2
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T131500Z
DTEND:20261006T133500Z
SUMMARY:GAME SHOW!! GAME SHOW!! Part Dva!! - Adrianne Marcum\, Linux Foundation & Christopher Robinson\, OpenSSF
DESCRIPTION:Bringing the same energy of the hit game show enjoyed at the 2026 OpenSSF Community Day North America to share with the European community with all new questions and the same security fun. \n Join the OpenSSF staff and community and pit your knowledge of our community against your peers in this interactive game that EVERYONE can play. Come be educated\, informed\, and entertained.
CATEGORIES:SECURING THE SOFTWARE SUPPLY CHAIN
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:96bc400dff2d478a5e3f64567462d05d
URL:http://openssfcdeu2026.sched.com/event/96bc400dff2d478a5e3f64567462d05d
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T133500Z
DTEND:20261006T140500Z
SUMMARY:Break
DESCRIPTION:\n
CATEGORIES:BREAKS & REGISTRATION
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:8c61f855d392770ba05ffced67f92237
URL:http://openssfcdeu2026.sched.com/event/8c61f855d392770ba05ffced67f92237
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T140500Z
DTEND:20261006T142500Z
SUMMARY:The Kernel Does Not Negotiate: Building the Tooling To Say No To AI Agents - Sal Kimmich\, NoLabs
DESCRIPTION:We give agents our full filesystem permissions because that is how Unix works. We give them network access because they need to call APIs. We give them access to credentials and shell history not because they need any of it\, but because we have not built the tooling to say: you can have this\, but not that. This talk is about building that tooling\, shipping it\, and being honest about what it does and does not solve. nono enforces per-tool-call restrictions at the kernel level using Linux Landlock. Real credentials never exist inside the agent's execution context. The audit log is written by a process outside the sandbox that the agent cannot reach. The kernel does not negotiate. Once the sandbox is applied it is irreversible. We show it working in production: Kubefence\, a Red Hat Kubernetes NRI plugin\, and the nono-py integration being merged into Microsoft's agent-governance-toolkit. The Secure Agentic Framework gives us a shared language for which attack classes this addresses. We will walk through that map carefully because an accurate map is needed for an agentic security model.
CATEGORIES:AI AND ML IN SECURITY
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:0ab0f0e4ecf8b86c0a833e8f81751c8e
URL:http://openssfcdeu2026.sched.com/event/0ab0f0e4ecf8b86c0a833e8f81751c8e
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T143000Z
DTEND:20261006T144500Z
SUMMARY:Verifiable AI Provenance: Closing the Attestation Gap in the Machine Learning Supply Chain - Sheng Sun\, Dell & Sarah Evans\, Dell Technologies
DESCRIPTION:AI/ML models remain outside established provenance frameworks such as SLSA\, in‑toto\, and SBOMs\, leaving deployments without hardware‑rooted origin\, signed attestations\, or a verifiable chain of custody. This talk presents practical results from implementing verifiable AI provenance in an operational MLOps pipeline and highlights four gaps: fragmented lineage\, unverifiable training environments\, unsigned model artifacts\, and non‑tamper‑evident pipeline history. We show how existing components—Marquez for lineage\, IETF RATS attestation for environment integrity\, SLSA plus Sigstore/cosign for artifact provenance\, and adapters binding OpenLineage/MLflow events into signed RATS tokens—compose into a unified\, auditable chain of custody. End‑to‑end evaluation demonstrates attestation‑gated workflows\, reproducible promotion decisions\, and detection of unverified or mis‑ordered stages. The result is a practical reference architecture for cryptographically anchored AI provenance that extends supply‑chain security across the ML lifecycle.
CATEGORIES:SECURING THE SOFTWARE SUPPLY CHAIN
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:f16946c10d8d9cce1cb9a6a38393b892
URL:http://openssfcdeu2026.sched.com/event/f16946c10d8d9cce1cb9a6a38393b892
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T145000Z
DTEND:20261006T150500Z
SUMMARY:Applying VEX To Vulnerability Information Sharing in Multi-tier Automotive Supply Chains - Yuta Kiyoumi\, Honda Motor Co.\, Ltd. & Akihiko Takahashi\, Fujitsu
DESCRIPTION:Automotive software\, including In-Vehicle Infotainment (IVI) systems\, is developed through multi-tier supply chains involving OEMs\, Tier-1 suppliers\, and other stakeholders. Under automotive cybersecurity regulations\, OEMs bear responsibility for managing vulnerabilities across the entire supply chain\, making the exchange and tracking of vulnerability impact assessments among suppliers a significant challenge. VEX has been identified as a promising mechanism that could distribute vulnerability impact assessments among suppliers in response to these challenges. Using IVI software development as a focus\, we verified whether suppliers at each tier can produce VEX documents for their own products\, and whether those assessments can be transmitted and utilized through a multi-tier supply chain while preserving their intended meaning. In this session\, we present practical design guidelines for applying VEX to multi-tier supply chains. We also introduce design and operational approaches that enable VEX-based vulnerability assessment distribution across complex supply chains beyond the automotive domain.
CATEGORIES:SECURING THE SOFTWARE SUPPLY CHAIN
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:e3ae6036bb0a3fd0a25f91c09b443827
URL:http://openssfcdeu2026.sched.com/event/e3ae6036bb0a3fd0a25f91c09b443827
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T151000Z
DTEND:20261006T153500Z
SUMMARY:Securing Africas Open Source Ecosysetm: Community Health\, Building Trust\, Resilient\, Sustainable Software - Ejiro Oghenekome\, Independent; Victoria Ottah\, Accessibility Nigeria ; Sal Kimmich\, NoLabs; Christopher Robinson\, OpenSSF; Amir Montazery\, OSTIF
DESCRIPTION:Open source software powers much of Africa's digital infrastructure. Across the continent\, communities are building new projects\, maintaining existing ones\, and adopting global technologies to accelerate innovation. \n As adoption grows\, so does the responsibility to secure the software supply chains these projects depend on. African organisations face limited cybersecurity resources\, inconsistent funding\, and uneven access to audits and tooling. \n But security depends as much on the people maintaining a project as on the tools they use. OpenSSF Scorecard\, OSPS Baseline\, and audits only matter if contributors are available to act on the results. Someone has to review findings\, fix vulnerabilities\, and keep the project healthy. \n This panel explores why community health is a security issue\, and why contributor retention\, trust\, and sustainable maintainership are essential to software security. \n Drawing on the OpenSSF Africa SIG\, CHAOSS community-health metrics\, and OSTIF's work supporting under-resourced projects\, panelists will discuss practical ways to build resilient communities\, use security guidance with limited resources\, and strengthen Africa's open source ecosystem.
CATEGORIES:CYBER RESILIENCE
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:819ab0734728f9107decbc6696ca1088
URL:http://openssfcdeu2026.sched.com/event/819ab0734728f9107decbc6696ca1088
END:VEVENT
BEGIN:VEVENT
DTSTAMP:20260722T234337Z
DTSTART:20261006T153500Z
DTEND:20261006T154000Z
SUMMARY:Keynote: Closing Remarks - Steve Fernandez\, OpenSSF Managing Director\, The Linux Foundation
DESCRIPTION:\n
CATEGORIES:KEYNOTE SESSIONS
LOCATION:South Hall 3B-3C\, Prague\, Czechia
SEQUENCE:0
UID:9ee7bb363184f9b1fc24cac34c698d3b
URL:http://openssfcdeu2026.sched.com/event/9ee7bb363184f9b1fc24cac34c698d3b
END:VEVENT
END:VCALENDAR
