Loading…
Tuesday October 6, 2026 11:45 - 12:00 CEST
We've all been new contributors at some point. You know the learning curve - best practices established before your first PR, specs that have been evolving for years. Should PRs require 3 reviewers? Do I need MFA? What are the actual threats to this project? Contributors need a clear way to understand not just how to contribute, but how to contribute securely.

The OpenSSF Gemara Project provides a standardized model and tooling to help projects define capabilities, identify threats, and document the controls that prevent them, structured across a 7-layer architecture. For maintainers shipping open source into the EU under the Cyber Resilience Act, structured governance isn't optional.
Speakers
avatar for Hannah Braswell

Hannah Braswell

Product Security Engineer, Red Hat
Hannah is an Associate Product Security Engineer at Red Hat, focused on securing complex open-source systems. She holds a B.S. in Computer Engineering from NC State University. An active contributor to several OpenSSF projects and Working Groups, she serves as Community Manager for... Read More →
Tuesday October 6, 2026 11:45 - 12:00 CEST
South Hall 3B-3C

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link