Loading…
Tuesday, October 6
 

08:00 CEST

Registration + Badge Pick-up
Tuesday October 6, 2026 08:00 - 17:40 CEST

Tuesday October 6, 2026 08:00 - 17:40 CEST

09:00 CEST

Keynote: Welcome & Opening Remarks - Steve Fernandez, OpenSSF Managing Director, The Linux Foundation
Tuesday October 6, 2026 09:00 - 09:10 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF Managing Director, The Linux Foundation

Tuesday October 6, 2026 09:00 - 09:10 CEST
South Hall 3B-3C

09:10 CEST

Keynote Sessions To Be Announced
Tuesday October 6, 2026 09:10 - 10:00 CEST

Tuesday October 6, 2026 09:10 - 10:00 CEST
South Hall 3B-3C

10:00 CEST

Break
Tuesday October 6, 2026 10:00 - 10:30 CEST

Tuesday October 6, 2026 10:00 - 10:30 CEST
South Hall 3B-3C

10:30 CEST

Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann, iRights.Law Rechtsanwälte
Tuesday October 6, 2026 10:30 - 10:50 CEST
On 8 Sept 2025, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone, who pays? Two EU laws finalised in 2024 shape the answer, the Product Liability Directive and the Cyber Resilience Act, and their duties phase in across 2026 and 2027. So...
See More →
Speakers
avatar for Annika Kristin Niemann

Annika Kristin Niemann

Lawyer, iRights.Law
Annika Niemann is a solicitor specialising in IT law, with a focus on open source compliance, supporting companies in the legally compliant use of open source software across the supply chain. She advises on CRA and product liability questions, including how the EU's Cyber Resilience... Read More →
Tuesday October 6, 2026 10:30 - 10:50 CEST
South Hall 3B-3C

10:55 CEST

Preparing for the Vulnpocalypse: Using OSS-CRS To Find and Fix Bugs Before They Find You - Jeff Diecks, OpenSSF & Laura Guazzelli, Linux Foundation
Tuesday October 6, 2026 10:55 - 11:15 CEST
The open source ecosystem faces a Vulnpocalypse as AI-driven vulnerability reports surge. While potentially beneficial for security long-term, the current volume threatens to overwhelm open source projects. Maintainers work at human speed, and each report requires careful attention, verification, and disclosure. So we need machines to help fix what the machines are finding. In this workshop.we...
See More →
Speakers
avatar for Jeff Diecks

Jeff Diecks

Senior Technical Program Manager, OpenSSF
Jeff Diecks is a Senior Technical Program Manager at The Linux Foundation. He has more than two decades of experience in technology and communications with a diverse background in operations, project management and executive leadership. A participant in open source since 1999, he’s... Read More →
avatar for Laura Guazzelli

Laura Guazzelli

Security Architect, Linux Foundation
Laura has experience helping engineering and product teams build security into the way they work. With a background spanning DevSecOps, CI/CD, platform security, and AI/ML governance, Laura focuses on people and processes behind security systems as much as the technology itself.
Tuesday October 6, 2026 10:55 - 11:15 CEST
South Hall 3B-3C

11:20 CEST

Defending Bare-Metal: Lessons Learnt From AI Security Analysis of Metal3 and OpenStack Ironic - Dmitry Tantsur, Red Hat & Tuomo Tanskanen, Ericsson Software Technology
Tuesday October 6, 2026 11:20 - 11:40 CEST
AI-powered vulnerability discovery is here, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze, especially as low-hanging fruit is rapidly plucked. In this session, maintainers...
See More →
Speakers
avatar for Dmitry Tantsur

Dmitry Tantsur

Senior Principal Software Engineer, Red Hat
Long-term Metal3 and Ironic developer, OpenShift Metal team lead. My point of expertise is bare-metal management and provisioning
avatar for Tuomo Tanskanen

Tuomo Tanskanen

Principal Security Developer, Ericsson Software Technology
Tuomo is a telecom software engineer with 20+ years of hands-on experience across major industry giants. With vast and versatile experience in product security, incident response, and penetration testing, he is currently a Principal Security Developer at Ericsson and is Maintainer... Read More →
Tuesday October 6, 2026 11:20 - 11:40 CEST
South Hall 3B-3C

11:45 CEST

From First PR To Hardening Guide: Structured Security With Gemara - Hannah Braswell, Red Hat
Tuesday October 6, 2026 11:45 - 12:00 CEST
We've all been new contributors at some point. You know the learning curve - best practices established before your first PR, specs that have been evolving for years. Should PRs require 3 reviewers? Do I need MFA? What are the actual threats to this project? Contributors need a clear way to understand not just how to contribute, but how to contribute securely. The OpenSSF Gemara Project provides...
See More →
Speakers
avatar for Hannah Braswell

Hannah Braswell

Product Security Engineer, Red Hat
Hannah is an Associate Product Security Engineer at Red Hat, focused on securing complex open-source systems. She holds a B.S. in Computer Engineering from NC State University. An active contributor to several OpenSSF projects and Working Groups, she serves as Community Manager for... Read More →
Tuesday October 6, 2026 11:45 - 12:00 CEST
South Hall 3B-3C

12:05 CEST

The SLSA Tooling Cake - Adolfo García Veytia, Carabiner Systems
Tuesday October 6, 2026 12:05 - 12:20 CEST
Starting in 2025, the SLSA project overhauled the tool catalog it maintains, unveiling new libraries and utilities while sunsetting older repositories that were not maintained any longer. The project has now overhauled the projects under the SLSA umbrella into a more coherent stack starting with the spec and definitions at the bottom all the way to community integrations at the top. This is what...
See More →
Speakers
avatar for Adolfo Garcia Veytia

Adolfo Garcia Veytia

Founding Engineer, Carabiner Systems
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Tuesday October 6, 2026 12:05 - 12:20 CEST
South Hall 3B-3C

12:25 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them. The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the...
See More →
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
South Hall 3B-3C

12:40 CEST

Lunch
Tuesday October 6, 2026 12:40 - 13:55 CEST

Tuesday October 6, 2026 12:40 - 13:55 CEST
South Hall 3B-3C

13:55 CEST

Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov, Red Hat; Daniel Appelquist, Samsung Electronics; Madalin Neag, OpenSSF; Megan Knight, Arm
Tuesday October 6, 2026 13:55 - 15:10 CEST
As of Sept 11, 2026, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet, Linux Foundation research shows 66% of the ecosystem remains unprepared, risking expensive "private forking" traps. Hosted by the OpenSSF Global Cyber Policy WG, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities a lot...
See More →
Speakers
avatar for Dan Appelquist

Dan Appelquist

Open Source Strategist, Samsung Electronics
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the OpenSSF Global Cyber Policy working group and also has been a member of the OpenSSF's... Read More →
avatar for Roman Zhukov

Roman Zhukov

Security Communities Lead, Red Hat
Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product... Read More →
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF
Madalin serves as EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
avatar for Megan Knight

Megan Knight

Director of Software Communities, Arm
Megan Knight is the Director of Software Communities at Arm where she leads upstream engagements with open source communities. She holds many leadership positions with various communities including Advocacy Chair for the Yocto Project, OSPO Special Interest Group lead for UXL Foundation... Read More →
Tuesday October 6, 2026 13:55 - 15:10 CEST
South Hall 3B-3C

15:15 CEST

GAME SHOW!! GAME SHOW!! Part Dva!! - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Tuesday October 6, 2026 15:15 - 15:35 CEST
Bringing the same energy of the hit game show enjoyed at the 2026 OpenSSF Community Day North America to share with the European community with all new questions and the same security fun.
Join the OpenSSF staff and community and pit your knowledge of our community against your peers in this interactive game that EVERYONE can play. Come be educated, informed, and entertained.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Cyber, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

OpenSSF Chief of Staff, Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across diverse industries, including defense, heavy machinery, mobility... Read More →
Tuesday October 6, 2026 15:15 - 15:35 CEST
South Hall 3B-3C

15:35 CEST

Break
Tuesday October 6, 2026 15:35 - 16:05 CEST

Tuesday October 6, 2026 15:35 - 16:05 CEST
South Hall 3B-3C

16:05 CEST

The Kernel Does Not Negotiate: Building the Tooling To Say No To AI Agents - Sal Kimmich, NoLabs
Tuesday October 6, 2026 16:05 - 16:25 CEST
We give agents our full filesystem permissions because that is how Unix works. We give them network access because they need to call APIs. We give them access to credentials and shell history not because they need any of it, but because we have not built the tooling to say: you can have this, but not that. This talk is about building that tooling, shipping it, and being honest about what it does...
See More →
Speakers
avatar for Sal Kimmich

Sal Kimmich

Security Architect, NoLabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
Tuesday October 6, 2026 16:05 - 16:25 CEST
South Hall 3B-3C

16:30 CEST

Verifiable AI Provenance: Closing the Attestation Gap in the Machine Learning Supply Chain - Sheng Sun, Dell & Sarah Evans, Dell Technologies
Tuesday October 6, 2026 16:30 - 16:45 CEST
AI/ML models remain outside established provenance frameworks such as SLSA, in‑toto, and SBOMs, leaving deployments without hardware‑rooted origin, signed attestations, or a verifiable chain of custody. This talk presents practical results from implementing verifiable AI provenance in an operational MLOps pipeline and highlights four gaps: fragmented lineage, unverifiable training...
See More →
Speakers
avatar for Sheng Sun

Sheng Sun

AI Security Researcher, Dell
Sheng Sun is a cybersecurity architect and AI security researcher with expertise in wireless security, trusted computing, and verifiable AI. At Huawei and Dell, he contributed to IEEE 802.11 and Wi‑Fi Alliance efforts, including WPA3. His work now focuses on attestation, AI integrity... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah Evans is a Distinguished Engineer and security applied research program lead at Dell Technologies, driving technical innovation for secure business outcomes. She is a recognized leader focusing on extending secure operations and supply chain principles to securing AI and agentic... Read More →
Tuesday October 6, 2026 16:30 - 16:45 CEST
South Hall 3B-3C

16:50 CEST

Applying VEX To Vulnerability Information Sharing in Multi-tier Automotive Supply Chains - Yuta Kiyoumi, Honda Motor Co., Ltd. & Akihiko Takahashi, Fujitsu
Tuesday October 6, 2026 16:50 - 17:05 CEST
Automotive software, including In-Vehicle Infotainment (IVI) systems, is developed through multi-tier supply chains involving OEMs, Tier-1 suppliers, and other stakeholders. Under automotive cybersecurity regulations, OEMs bear responsibility for managing vulnerabilities across the entire supply chain, making the exchange and tracking of vulnerability impact assessments among suppliers a...
See More →
Speakers
avatar for Yuta KIYOUMI

Yuta KIYOUMI

Assistant Chief Engineer, Honda Motor Co., Ltd.
Yuta Kiyoumi is the Security Architect for IVI software development at Honda Motor Co., Ltd. He also serves as a member of the Honda OSPO promoting secure OSS adoption, and participates as a member of the OpenSSF.
avatar for Akihiko Takahashi

Akihiko Takahashi

OpenSSF Community Member, Fujitsu
Linux distributors for Edge computing machines
Tuesday October 6, 2026 16:50 - 17:05 CEST
South Hall 3B-3C

17:10 CEST

Securing Africas Open Source Ecosysetm: Community Health, Building Trust, Resilient, Sustainable Software - Ejiro Oghenekome, Independent; Victoria Ottah, Accessibility Nigeria ; Sal Kimmich, NoLabs; Christopher Robinson, OpenSSF; Amir Montazery, OSTIF
Tuesday October 6, 2026 17:10 - 17:35 CEST
Open source software powers much of Africa's digital infrastructure. Across the continent, communities are building new projects, maintaining existing ones, and adopting global technologies to accelerate innovation. As adoption grows, so does the responsibility to secure the software supply chains these projects depend on. African organisations face limited cybersecurity resources, inconsistent...
See More →
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Cyber, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Victoria Ottah

Victoria Ottah

Accessibility lead, Accessibility Nigeria
Toria is a UX designer, global speaker, and recognized A11y Evangelist dedicated to digital inclusion. She co-wrote the first digital ethical accessibility book and conducts crucial accessibility audits.
As the founder of Accessibility Nigeria, a WomenTech Network Ambassador/Adv... Read More →
avatar for Sal Kimmich

Sal Kimmich

Security Architect, NoLabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
avatar for Amir Montazery

Amir Montazery

Managing Director, Open Source Technology Improvement Fund, Inc (OSTIF)
Amir Montazery is the Managing Director and Cofounder of Open Source Technology Improvement Fund, Inc (OSTIF). OSTIF is a Chicago-based organization focused on directly helping open-source software projects improve their security posture. Amir comes from a background in Finance, IT... Read More →
avatar for Ejiro Oghenekome

Ejiro Oghenekome

Cybersecurity Analyst and OpenSSF Ambassador, Independent

Tuesday October 6, 2026 17:10 - 17:35 CEST
South Hall 3B-3C

17:35 CEST

Keynote: Closing Remarks - Steve Fernandez, OpenSSF Managing Director, The Linux Foundation
Tuesday October 6, 2026 17:35 - 17:40 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF Managing Director, The Linux Foundation

Tuesday October 6, 2026 17:35 - 17:40 CEST
South Hall 3B-3C
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.