Loading…
Tuesday October 6, 2026 10:55 - 11:15 CEST
The open source ecosystem faces a Vulnpocalypse as AI-driven vulnerability reports surge. While potentially beneficial for security long-term, the current volume threatens to overwhelm open source projects. Maintainers work at human speed, and each report requires careful attention, verification, and disclosure.

So we need machines to help fix what the machines are finding.

In this workshop.we will walk through OSS-CRS. It's an OpenSSF project that gives us a standard orchestration framework for Cyber Reasoning Systems (CRS) capable of finding, proving and patching vulnerabilities.

Beyond the technology, we examine critical best practices for CRS usage. This includes how to build community norms that respect a maintainer's time instead of just dumping more work on their plate.

Attendees will learn:
- The current trends of AI-generated reports and the impact on open source
- How to run OSS-CRS for bug finding and fixing.
- Best practices for responsible use of AI tools in CVD.
Speakers
avatar for Jeff Diecks

Jeff Diecks

Senior Technical Program Manager, OpenSSF
Jeff Diecks is a Senior Technical Program Manager at The Linux Foundation. He has more than two decades of experience in technology and communications with a diverse background in operations, project management and executive leadership. A participant in open source since 1999, he’s... Read More →
avatar for Laura Guazzelli

Laura Guazzelli

Security Architect, Linux Foundation
Laura has experience helping engineering and product teams build security into the way they work. With a background spanning DevSecOps, CI/CD, platform security, and AI/ML governance, Laura focuses on people and processes behind security systems as much as the technology itself.
Tuesday October 6, 2026 10:55 - 11:15 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link