Loading…
Tuesday, October 6
 

07:30 CEST

Registration + Badge Pick-up
Tuesday October 6, 2026 07:30 - 17:00 CEST

Tuesday October 6, 2026 07:30 - 17:00 CEST
Congress Hall Foyer

09:00 CEST

Keynote: Welcome & Opening Remarks - Steve Fernandez, OpenSSF General Manager, The Linux Foundation
Tuesday October 6, 2026 09:00 - 09:10 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF General Manager, The Linux Foundation

Tuesday October 6, 2026 09:00 - 09:10 CEST
South Hall 3B

09:10 CEST

Keynote Sessions To Be Announced
Tuesday October 6, 2026 09:10 - 09:25 CEST

Tuesday October 6, 2026 09:10 - 09:25 CEST
South Hall 3B

09:25 CEST

Keynote: Who Funds the Toolchain? Secure Infrastructure for GLIBC and the GNU Toolchain - Kris Borchers, Senior Technical Program Manager, OpenSSF & Carlos O'Donell, Distinguished Engineer, Red Hat
Tuesday October 6, 2026 09:25 - 09:40 CEST
The GNU toolchain sits underneath a huge amount of the software the world relies on. GLIBC is a good place to start that conversation because so much depends on it, yet the systems behind projects like this often get far less attention than the code itself.This keynote looks at why secure, reliable project infrastructure has become part of the open source security conversation. Source control,...
See More →
Speakers
avatar for Kris Borchers

Kris Borchers

Senior Technical Program Manager, OpenSSF

avatar for Carlos O'Donell

Carlos O'Donell

Distinguished Engineer, Red Hat
Leading a team of passionate and dedicated developer to enhance and develop core runtimes for Red Hat Enterprise Linux and the layered products and stacks.

Looking forward to advancing the state of free and open-source system libraries and tooling used by developers. Always interested in low-level aspects of software and hardware interaction and how they effect the system as a whole, including hardware, kernel and core library design... Read More →
Tuesday October 6, 2026 09:25 - 09:40 CEST
South Hall 3B

09:45 CEST

Keynote Sessions To Be Announced
Tuesday October 6, 2026 09:45 - 10:00 CEST

Tuesday October 6, 2026 09:45 - 10:00 CEST
South Hall 3B

10:00 CEST

Break
Tuesday October 6, 2026 10:00 - 10:30 CEST

Tuesday October 6, 2026 10:00 - 10:30 CEST
South Hall 3C

10:30 CEST

SCORED Opening Remarks
Tuesday October 6, 2026 10:30 - 10:40 CEST

Tuesday October 6, 2026 10:30 - 10:40 CEST
South Hall 3A

10:30 CEST

Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann, iRights.Law Rechtsanwälte
Tuesday October 6, 2026 10:30 - 10:50 CEST
On 8 Sept 2025, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone, who pays? Two EU laws finalised in 2024 shape the answer, the Product Liability Directive and the Cyber Resilience Act, and their duties phase in across 2026 and 2027. So...
See More →
Speakers
avatar for Annika Kristin Niemann

Annika Kristin Niemann

Lawyer, iRights.Law
Annika Niemann is a solicitor specialising in IT law, with a focus on open source compliance, supporting companies in the legally compliant use of open source software across the supply chain. She advises on CRA and product liability questions, including how the EU's Cyber Resilience... Read More →
Tuesday October 6, 2026 10:30 - 10:50 CEST
South Hall 3B

10:40 CEST

Ghost In The Codebase - Why Your LLM Needs a SCA/SAST Babysitter - Luca Galli, Open Systems AG
Tuesday October 6, 2026 10:40 - 11:00 CEST
As software development accelerates with the rise of autonomous agents and “Agentic Vibe Coding”, the introduction of vulnerabilities into codebases is scaling correspondingly. While Artificial Intelligence and Large Language Models (LLMs) act as proficient developers, they are frequently trained on potentially insecure data from unverified platforms like GitHub and HuggingFace, making them...
See More →
Speakers
avatar for Luca Galli

Luca Galli

Senior Application Security Engineer, Open Systems AG
Luca Galli, PhD, is a Senior Application Security Engineer II at Open Systems, where he specializes in application security, DevSecOps, and AI security. He drives the protection of complex multi-language monorepos and leverages AI to automate security pipelines, streamlining vulnerability... Read More →
Tuesday October 6, 2026 10:40 - 11:00 CEST
South Hall 3A

10:55 CEST

Preparing for the Vulnpocalypse: Using OSS-CRS To Find and Fix Bugs Before They Find You - Jeff Diecks, OpenSSF; Laura Guazzelli, Linux Foundation & Andrew Chin, Georgia Institute of Technology
Tuesday October 6, 2026 10:55 - 11:15 CEST
The open source ecosystem faces a Vulnpocalypse as AI-driven vulnerability reports surge. While potentially beneficial for security long-term, the current volume threatens to overwhelm open source projects. Maintainers work at human speed, and each report requires careful attention, verification, and disclosure. So we need machines to help fix what the machines are finding. In this workshop.we...
See More →
Speakers
avatar for Jeff Diecks

Jeff Diecks

Senior Technical Program Manager, OpenSSF
Jeff Diecks is a Senior Technical Program Manager at The Linux Foundation. He has more than two decades of experience in technology and communications with a diverse background in operations, project management and executive leadership. A participant in open source since 1999, he’s... Read More →
avatar for Laura Guazzelli

Laura Guazzelli

Security Architect - AI/ML/LLM/Agentic Systems, OpenSSF - Linux Foundation
Laura has experience helping engineering and product teams build security into the way they work. With a background spanning DevSecOps, CI/CD, platform security, and AI/ML governance, Laura focuses on people and processes behind security systems as much as the technology itself.
avatar for Andrew Chin

Andrew Chin

Ph.D. Student, Georgia Institute of Technology

Tuesday October 6, 2026 10:55 - 11:15 CEST
South Hall 3B

11:02 CEST

The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort - Aleksandr Churilov, Independent Researcher
Tuesday October 6, 2026 11:02 - 11:20 CEST
Spracklen et al. (USENIX Security '25) showed that code-generating large language models hallucinate package names that do not exist on PyPI or npm at rates ranging from 5.2% on commercial models to 21.7% on open-source models, creating an attack surface for slopsquatting—the registration of malicious packages under hallucinated names. We replicate their methodology on five frontier code-capable...
See More →
Speakers
AC

Aleksandr Churilov

Independent researcher
Aleksandr Churilov is an independent security researcher working on the safety of LLM-based systems, with a focus on the supply-chain and agent-security failure modes that appear as models move into real developer workflows. His recent work replicated and extended the measurement... Read More →
Tuesday October 6, 2026 11:02 - 11:20 CEST
South Hall 3A

11:20 CEST

Defending Bare-Metal: Lessons Learnt From AI Security Analysis of Metal3 and OpenStack Ironic - Dmitry Tantsur, Red Hat & Tuomo Tanskanen, Ericsson Software Technology
Tuesday October 6, 2026 11:20 - 11:40 CEST
AI-powered vulnerability discovery is here, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze, especially as low-hanging fruit is rapidly plucked. In this session, maintainers...
See More →
Speakers
avatar for Dmitry Tantsur

Dmitry Tantsur

Senior Principal Software Engineer, Red Hat
Long-term Metal3 and Ironic developer, OpenShift Metal team lead. My point of expertise is bare-metal management and provisioning
avatar for Tuomo Tanskanen

Tuomo Tanskanen

Principal Security Developer, Ericsson Software Technology
Tuomo is a telecom software engineer with 20+ years of hands-on experience across major industry giants. With vast and versatile experience in product security, incident response, and penetration testing, he is currently a Principal Security Developer at Ericsson and is Maintainer... Read More →
Tuesday October 6, 2026 11:20 - 11:40 CEST
South Hall 3B

11:22 CEST

SandScope: A Behavioral Audit Layer for MCP Tools in LLM Agent Supply Chains - Zhuoran Tan, University of Glasgow
Tuesday October 6, 2026 11:22 - 11:40 CEST
Tool-augmented Large Language Model (LLM) agents create a new supply-chain surface: Model Context Protocol (MCP) tools are installed like third-party packages, yet their outputs can enter the agent’s reasoning context. This enables confused-deputy risks in which attacker-controlled semantic supply-chain inputs cause otherwise benign tools to exercise legitimate authority over files, environment...
See More →
Speakers
avatar for Zhuoran Tan

Zhuoran Tan

Security Researcher, University of Glasgow
Zhuoran (Newt) Tan is a security researcher specialising in AI/LLM security, software supply chain security, and runtime threat detection. He recently completed his PhD in Computing Science at the University of Glasgow, where his research focused on runtime observability and security... Read More →
Tuesday October 6, 2026 11:22 - 11:40 CEST
South Hall 3A

11:42 CEST

Librarian Catches Thief: Surfacing Supply Chain Attack Campaigns via Document Similarity in an AI Agent Skill Registry - Gale Fagan, Brightflag
Tuesday October 6, 2026 11:42 - 12:00 CEST
Supply chain attack campaigns mass-produce their artifacts, and mass production leaves a structural trace: hundreds of near-identical files. In AI agent skill marketplaces, which distribute capabilities as natural-language instruction files following the Agent Skills standard (an open format adopted by over 30 platforms), the artifact carrying that trace is a document, readable by document...
See More →
Speakers
GF

Gale Fagan

Principal AI Architect, Brightflag
Gale Fagan is a Principal AI Architect at Brightflag, a Wolters Kluwer legal-tech company. Over nearly thirty years, she has held engineering, architecture, and executive roles at Apple, Uber, HashiCorp, Nervana (later Intel), dv01, and ISC, where she helped keep f.root-servers.net... Read More →
Tuesday October 6, 2026 11:42 - 12:00 CEST
South Hall 3A

11:45 CEST

From First PR To Hardening Guide: Structured Security With Gemara - Hannah Braswell, Red Hat
Tuesday October 6, 2026 11:45 - 12:00 CEST
We've all been new contributors at some point. You know the learning curve - best practices established before your first PR, specs that have been evolving for years. Should PRs require 3 reviewers? Do I need MFA? What are the actual threats to this project? Contributors need a clear way to understand not just how to contribute, but how to contribute securely. The OpenSSF Gemara Project provides...
See More →
Speakers
avatar for Hannah Braswell

Hannah Braswell

Associate Product Security Engineer, Red Hat, Inc.
Hannah is an Associate Product Security Engineer at Red Hat, focused on securing complex open-source systems. She holds a B.S. in Computer Engineering from NC State University. An active contributor to several OpenSSF projects and Working Groups, she serves as Community Manager for... Read More →
Tuesday October 6, 2026 11:45 - 12:00 CEST
South Hall 3B

12:02 CEST

When Models Meet Loaders: Deserialization Risk in Huggingface - Xiang (Shawn) Guo, Victoria University of Wellington
Tuesday October 6, 2026 12:02 - 12:20 CEST
Machine learning models are increasingly distributed through centralized repositories such as Hugging Face. These models rely on a variety of serialization formats and on complex software libraries for deserialization. This introduces risks into the supply chains of applications using those models as deserialization is prone to vulnerabilities. In this paper, we study and quantify this risk by...
See More →
Speakers
XS

Xiang (Shawn) Guo

Doctor of Philosophy in Computer Science, Victoria University of Wellington
Xiang (Shawn) Guo is a Doctor of Philosophy in Computer Science Researching AI Software Supply Chain Security and Deserialization Vulnerability in AI
Tuesday October 6, 2026 12:02 - 12:20 CEST
South Hall 3A

12:05 CEST

The SLSA Tooling Cake - Adolfo García Veytia, Carabiner Systems
Tuesday October 6, 2026 12:05 - 12:20 CEST
Starting in 2025, the SLSA project overhauled the tool catalog it maintains, unveiling new libraries and utilities while sunsetting older repositories that were not maintained any longer. The project has now overhauled the projects under the SLSA umbrella into a more coherent stack starting with the spec and definitions at the bottom all the way to community integrations at the top. This is what...
See More →
Speakers
avatar for Adolfo Garcia Veytia

Adolfo Garcia Veytia

Founding Engineer, Carabiner Systems
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Tuesday October 6, 2026 12:05 - 12:20 CEST
South Hall 3B

12:22 CEST

SoK: What Software Supply Chain Security Can Learn from Decades of Physical Supply Chain Risk Management - Linus Kühl, FH Münster
Tuesday October 6, 2026 12:22 - 12:40 CEST
Software supply chain security is rapidly building its own risk-management toolbox: software bills of materials (SBOMs), provenance and build-integrity frameworks such as SLSA, dependency graphs, and repository-health scorecards. Physical supply chain risk management (SCRM) has spent decades developing structurally similar instruments, including multi-tier visibility programs, criticality and...
See More →
Speakers
LK

Linus Kühl

Doctoral Researcher and Lecturer, FH Münster

Tuesday October 6, 2026 12:22 - 12:40 CEST
South Hall 3A

12:25 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them. The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the...
See More →
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
South Hall 3B

12:40 CEST

Lunch
Tuesday October 6, 2026 12:40 - 13:55 CEST

Tuesday October 6, 2026 12:40 - 13:55 CEST
South Hall 3C

13:55 CEST

Canary in the Code Mine: Predictive Risk Scoring for Open-Source Supply Chain Security - Timothy Brennan, Raytheon
Tuesday October 6, 2026 13:55 - 14:15 CEST
Most organizations that consume open-source software remain reactive when assessing component security risk. CVE disclosures, CVSS severity scores, and EPSS exploit predictions are valuable, but they generally become useful only after a vulnerability has already been discovered and publicly disclosed.
Speakers
TB

Timothy Brennan

Principal Software Engineer, Raytheon
Tim Brennan is a Principal Software Engineer at Raytheon, an RTX business, with 30 years of experience in software engineering. He is also a Doctor of Engineering candidate in Cybersecurity Analytics at The George Washington University, where his praxis research developed CANARY... Read More →
Tuesday October 6, 2026 13:55 - 14:15 CEST
South Hall 3A

13:55 CEST

Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov, Red Hat; Daniel Appelquist, Samsung Electronics; Madalin Neag, OpenSSF; Megan Knight, Arm
Tuesday October 6, 2026 13:55 - 14:25 CEST
As of Sept 11, 2026, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet, Linux Foundation research shows 66% of the ecosystem remains unprepared, risking expensive "private forking" traps. Hosted by the OpenSSF Global Cyber Policy WG, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities a lot...
See More →
Speakers
avatar for Dan Appelquist

Dan Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the OpenSSF Global Cyber Policy working group and also has been a member of the OpenSSF's... Read More →
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product... Read More →
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, The Linux Foundation

avatar for Megan Knight

Megan Knight

Director Software Communities, Arm
Megan Knight is the Director of Software Communities at Arm where she leads upstream engagements with open source communities. She holds many leadership positions with various communities including Advocacy Chair for the Yocto Project, OSPO Special Interest Group lead for UXL Foundation... Read More →
Tuesday October 6, 2026 13:55 - 14:25 CEST
South Hall 3B

14:17 CEST

No Snake Oil: Verifying Python Package Builds - Jens Dietrich, Victoria University of Wellington
Tuesday October 6, 2026 14:17 - 14:35 CEST
Python has become the default language for interacting with AI, with packages being distributed through registries like the Python Package Index (PyPi). This creates a need to analyse supply chains comprising such packages. One such analysis is to rebuild packages in order to identify compromised builds injecting malware. Independent rebuilds in hardened environments have the added advantage that...
See More →
Speakers
JD

Jens Dietrich

Victoria University of Wellington
Jens is an Associate Professor in the School of Engineering and Computer Science (ECS) at Victoria University of Wellington in Wellington, New Zealand. He has a Master in Mathematics and a PhD in Computer Science from the University of Leipzig in Germany. After graduating in 1996... Read More →
Tuesday October 6, 2026 14:17 - 14:35 CEST
South Hall 3A

14:30 CEST

GAME SHOW!! GAME SHOW!! Part Dva!! - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Tuesday October 6, 2026 14:30 - 14:50 CEST
Bringing the same energy of the hit game show enjoyed at the 2026 OpenSSF Community Day North America to share with the European community with all new questions and the same security fun.
Join the OpenSSF staff and community and pit your knowledge of our community against your peers in this interactive game that EVERYONE can play. Come be educated, informed, and entertained.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Chief Architect - OpenSSF, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

Chief of Staff, OpenSSF, The Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across a multitude of industries, including defense, heavy machinery... Read More →
Tuesday October 6, 2026 14:30 - 14:50 CEST
South Hall 3B

14:37 CEST

Hurry Up and Wait: Malware Detection Timelines and Minimum Release Age for npm - Dominic Tassio, University of Kansas
Tuesday October 6, 2026 14:37 - 14:55 CEST
Setting a minimum release age is a new feature of npm, pnpm, Yarn, and other package managers, introduced to provide a mechanism for mitigating the impact of malware being uploaded to npm. However, no evidence-based analysis has been performed to determine how this security mechanism should be tuned to make effective use of it. To close this gap, we analyze the GitHub Advisory Database to collect...
See More →
Speakers
DT

Dominic Tassio

PhD Student, University of Kansas
Dominic is a PhD student in Computer Science at the University of Kansas's Institute for Information Sciences. His research explores programming language ecosystems and software supply-chain security, particularly within npm. He previously presented at SCORED '25 on the usage of HTTP(S... Read More →
Tuesday October 6, 2026 14:37 - 14:55 CEST
South Hall 3A

14:55 CEST

When Maintainers Move On: Detecting and Communicating Abandoned Open-source Projects - Felix Lange, SAP SE
Tuesday October 6, 2026 14:55 - 15:15 CEST
Like any other software, open-source projects may become unmaintained or abandoned over time for various reasons. Unlike commercial software, the end of support for open-source projects or versions is often not announced upfront but happens gradually, e.g. due to personal reasons on the maintainer’s side. For consumers, this raises the challenge of identifying abandoned open-source components in...
See More →
Speakers
avatar for Felix Lange

Felix Lange

Open Source Security Architect, SAP SE
Felix Lange is an open-source security architect at SAP focused on securing open-source consumption and contribution. In this role, he also contributes to SAP’s Secure Software Development and Operations Lifecycle. Over the past four years, he has focused on scoring dependencies... Read More →
Tuesday October 6, 2026 14:55 - 15:15 CEST
South Hall 3B

14:57 CEST

Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis - Romain Lefeuvre, IRISA, Inria
Tuesday October 6, 2026 14:57 - 15:15 CEST
Tracking vulnerabilities inherited from third-party open-source software is a well-known challenge, often addressed by tracing the threads of dependency information. At scale, existing approaches precompute the vulnerable versions of software associated with known CVEs, based on declared impacted versions or using local history analysis. However, vulnerabilities can also propagate through forking:...
See More →
Speakers
RL

Romain Lefeuvre

PhD Student, IRISA, Inria
Romain Lefeuvre is a PhD student in software engineering at the DiverSE team (IRISA, Inria, University of Rennes), supervised by Professor Benoit Combemale. His research explores how diversity, in open-source ecosystems, in software features, and in development processes, impacts... Read More →
Tuesday October 6, 2026 14:57 - 15:15 CEST
South Hall 3A

15:15 CEST

Break
Tuesday October 6, 2026 15:15 - 15:45 CEST

Tuesday October 6, 2026 15:15 - 15:45 CEST
South Hall 3C

15:45 CEST

Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations - Abhishek Reddypalle, Purdue University & Dennis Roellke, Bloomberg
Tuesday October 6, 2026 15:45 - 16:03 CEST
Modern software supply chains have evolved into vast, heterogeneous networks where transparency — the granular understanding of all software components — is now a critical security requirement. While Software Bills of Materials (SBOMs) have emerged as the primary mechanism for this transparency, current industry practices rely on a metadata-centric paradigm that assumes an artifact is defined...
See More →
Speakers
DR

Dennis Roellke

Security Architect, Office of the CTO, Bloomberg
Dennis Roellke is a Security Architect in the Office of the CTO at Bloomberg, where he provides strategic advice to the company's software supply chain security program. His influence spans multiple departments within the firm, orchestrating a secure software development lifecycle... Read More →
AR

Abhishek Reddypalle

PhD Researcher, Trustworthy Software Ecosystems Lab, Purdue University
Abhishek Reddypalle is a PhD researcher at Purdue University's Trustworthy Software Ecosystems Lab, where he works on software supply-chain security. His research includes work on reproducible builds and SBOM completeness, with a focus on build-time techniques for producing SBOMs... Read More →
Tuesday October 6, 2026 15:45 - 16:03 CEST
South Hall 3A

15:45 CEST

The Kernel Does Not Negotiate: Building the Tooling To Say No To AI Agents - Sal Kimmich, NoLabs
Tuesday October 6, 2026 15:45 - 16:05 CEST
We give agents our full filesystem permissions because that is how Unix works. We give them network access because they need to call APIs. We give them access to credentials and shell history not because they need any of it, but because we have not built the tooling to say: you can have this, but not that. This talk is about building that tooling, shipping it, and being honest about what it does...
See More →
Speakers
avatar for Sal Kimmich

Sal Kimmich

Security Architect, nolabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
Tuesday October 6, 2026 15:45 - 16:05 CEST
South Hall 3B

16:04 CEST

When Dependencies Become Lemons: A Multivocal Review of Cheap Trust Signal Collapse in the Software Supply Chain - Ranindya Paramitha, North Carolina State University
Tuesday October 6, 2026 16:04 - 16:22 CEST
Practitioners evaluating open-source dependencies rely on cheap trust signals, e.g., stars, download counts, and contributor activity, as substitutes for direct code inspection, assuming those signals reflect genuine trustworthiness. Prior work has documented individual signal gaming, but the landscape of collapses across all dependency-adoption signals, as well as the ecosystem’s response,...
See More →
Speakers
RP

Ranindya Paramitha

North Carolina State University
Ranindya Paramitha is an incoming Lecturer at the University of Bristol, UK. The presented work was completed when she was a Postdoctoral Research Scholar at North Carolina State University, USA. She received her PhD from the University of Trento, Italy. Her research focuses on software... Read More →
Tuesday October 6, 2026 16:04 - 16:22 CEST
South Hall 3A

16:10 CEST

Verifiable AI Provenance: Closing the Attestation Gap in the Machine Learning Supply Chain - Sheng Sun, Dell & Sarah Evans, Dell Technologies
Tuesday October 6, 2026 16:10 - 16:25 CEST
AI/ML models remain outside established provenance frameworks such as SLSA, in‑toto, and SBOMs, leaving deployments without hardware‑rooted origin, signed attestations, or a verifiable chain of custody. This talk presents practical results from implementing verifiable AI provenance in an operational MLOps pipeline and highlights four gaps: fragmented lineage, unverifiable training...
See More →
Speakers
avatar for Sheng Sun

Sheng Sun

Consultant, Software Technologist, Dell
Sheng Sun is a cybersecurity architect and AI security researcher with expertise in wireless security, trusted computing, and verifiable AI. At Huawei and Dell, he contributed to IEEE 802.11 and Wi‑Fi Alliance efforts, including WPA3. His work now focuses on attestation, AI integrity... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah Evans is a Distinguished Engineer and security applied research program lead at Dell Technologies, driving technical innovation for secure business outcomes. She is a recognized leader focusing on extending secure operations and supply chain principles to securing AI and agentic... Read More →
Tuesday October 6, 2026 16:10 - 16:25 CEST
South Hall 3B

16:23 CEST

Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation - Aman Sharma, KTH Royal Institute of Technology
Tuesday October 6, 2026 16:23 - 16:41 CEST
Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is widely regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only...
See More →
Speakers
avatar for Aman Sharma

Aman Sharma

PhD Student, KTH Royal Institute of Technology
Aman Sharma is a doctoral researcher at KTH Royal Institute of Technology in Stockholm, where he works on software supply chain security. His research digs into how we can trust the software we depend on. His expertise spans the Maven/Java ecosystem and the broader open-source supply... Read More →
Tuesday October 6, 2026 16:23 - 16:41 CEST
South Hall 3A

16:30 CEST

Applying VEX To Vulnerability Information Sharing in Multi-tier Automotive Supply Chains - Yuta Kiyoumi, Honda Motor Co., Ltd. & Akihiko Takahashi, Fujitsu
Tuesday October 6, 2026 16:30 - 16:45 CEST
Automotive software, including In-Vehicle Infotainment (IVI) systems, is developed through multi-tier supply chains involving OEMs, Tier-1 suppliers, and other stakeholders. Under automotive cybersecurity regulations, OEMs bear responsibility for managing vulnerabilities across the entire supply chain, making the exchange and tracking of vulnerability impact assessments among suppliers a...
See More →
Speakers
avatar for Yuta KIYOUMI

Yuta KIYOUMI

staff, HONDA MOTOR CO.,LTD.
Yuta Kiyoumi is the Security Architect for IVI software development at Honda Motor Co., Ltd. He also serves as a member of the Honda OSPO promoting secure OSS adoption, and participates as a member of the OpenSSF.
avatar for Akihiko Takahashi

Akihiko Takahashi

Member, Fujitsu Ltd
Linux distributors for Edge computing machines
Tuesday October 6, 2026 16:30 - 16:45 CEST
South Hall 3B

16:42 CEST

When SBOMs Differ: A Large-Scale Empirical Study of Generation, Dependency Structure, and Regulatory Alignment - Lukas Gehrke, Technical University of Munich
Tuesday October 6, 2026 16:42 - 17:00 CEST
Modern software relies on a multitude of dependencies, meaning a single compromised library can jeopardize all downstream software. Attackers increasingly exploit this structural weakness, leading to a proliferation of supply chain attacks with severe consequences across the broader software landscape. Recent legislation proposes using SBOMs to address this threat. However, researchers have...
See More →
Speakers
LG

Lukas Gehrke

Doctoral Candidate, Technical University of Munich
Lukas Gehrke is a doctoral candidate at Technical University of Munich. His research focuses on software supply chain security and how software bills of materials (SBOMs) can help achieve it.
Tuesday October 6, 2026 16:42 - 17:00 CEST
South Hall 3A

16:50 CEST

Securing Africas Open Source Ecosysetm: Community Health, Building Trust, Resilient, Sustainable Software - Ejiro Oghenekome, Independent; Victoria Ottah, Accessibility Nigeria ; Sal Kimmich, NoLabs; Christopher Robinson, OpenSSF; Amir Montazery, OSTIF
Tuesday October 6, 2026 16:50 - 17:15 CEST
Open source software powers much of Africa's digital infrastructure. Across the continent, communities are building new projects, maintaining existing ones, and adopting global technologies to accelerate innovation. As adoption grows, so does the responsibility to secure the software supply chains these projects depend on. African organisations face limited cybersecurity resources, inconsistent...
See More →
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Chief Architect - OpenSSF, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Victoria Ottah

Victoria Ottah

Accessibility Lead/Maintainer, CHAOSS
Toria is a UX designer, global speaker, and recognized A11y Evangelist dedicated to digital inclusion. She co-wrote the first digital ethical accessibility book and conducts crucial accessibility audits.
As the founder of Accessibility Nigeria, a WomenTech Network Ambassador/Adv... Read More →
avatar for Sal Kimmich

Sal Kimmich

Security Architect, nolabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
avatar for Amir Montazery

Amir Montazery

Managing Director, Open Source Technology Improvement Fund, Inc (OSTIF)
Amir Montazery is the Managing Director and Cofounder of Open Source Technology Improvement Fund, Inc (OSTIF). OSTIF is a Chicago-based organization focused on directly helping open-source software projects improve their security posture. Amir comes from a background in Finance, IT... Read More →
avatar for Ejiro Oghenekome

Ejiro Oghenekome

Cybersecurity Analyst/Researcher, OpenSSF

Tuesday October 6, 2026 16:50 - 17:15 CEST
South Hall 3B

17:01 CEST

Mind the Gap: How SBOM Specification Ambiguities Lead to Divergent Software Bills of Materials. An Empirical Tool Study - Philippe Boinot, ANSSI; Olivier Zendra & Alan Prado, Inria Rennes
Tuesday October 6, 2026 17:01 - 17:19 CEST
Software Bill of Materials (SBOMs) will become mandatory starting in September 2026 under the European Cyber Resilience Act (CRA) [8]. Although previous studies have highlighted significant differences among SBOM generators, the reasons for these discrepancies remain unknown, as does whether they stem from implementation errors or deliberate design choices. In this paper, we evaluate three widely...
See More →
Speakers
PB

Philippe Boinot

Researcher, French National Cybersecurity Agency (ANSSI)
Dr Philippe Boinot joined the French National Cybersecurity Agency (ANSSI) in September 2024, where his research focuses on software security, with a particular interest in software supply chain security.
AP

Alan Prado

Research Engineer, Inria Rennes, France,
Alan Prado is a research engineer at Inria, Rennes, France, working on the evaluation and quality of Software Bill of Materials produced by open-source tools. Previously, he worked on SBOM-related topics at ANSSI.
Tuesday October 6, 2026 17:01 - 17:19 CEST
South Hall 3A

17:20 CEST

SBOMs Are Useless Without Discoverability - Mario Fahlandt & Koray Oksay, Kubermatic
Tuesday October 6, 2026 17:20 - 17:35 CEST
SBOM generation is a solved problem. Syft, Trivy, and many more tools spit them out by the thousands. But what happens next? In most enterprises: nothing. SBOMs land in a bucket or CI artifact, and nobody looks at them again. The real challenge isn't producing SBOMs; it's making them actionable at scale.This talk introduces BOMHort, an open source Kubernetes-native platform for SBOM consumption,...
See More →
Speakers
avatar for Mario Fahlandt

Mario Fahlandt

Customer Delivery Architect, Kubermatic
Mario Fahlandt is a CNCF Technical Oversight Committee member, SIG ContribEx co-chair, and Kubernetes AI Conformance subproject lead. He maintains cncf/sbom, the project generating SPDX SBOMs for every CNCF release, and created SeeBOM, an open-source SBOM governance platform now applying... Read More →
avatar for Koray Oksay

Koray Oksay

Consultant, Kubermatic
Koray works at Kubermatic as a Kubernetes Consultant and Trainer, helping companies on their cloud-native journey. Before that, Koray worked for startup and enterprise companies in the advertising, banking, and telecom industries as a SysAdmin, Application Admin, DevOps Engineer... Read More →
Tuesday October 6, 2026 17:20 - 17:35 CEST
South Hall 3B

17:20 CEST

Over the Shoulder: Improving SBOM Accuracy by Watching the Build - Sanchit Sahay, New York University
Tuesday October 6, 2026 17:20 - 17:38 CEST
Software Bills of Materials (SBOMs) are increasingly used as authoritative software inventories but popular generators use techniques that may not expose every input that ends up in or influences a build artifact. This paper presented SBOMit, an OpenSSF project that generates and enriches SBOMs using evidence collected while the software build workflow executes. \texttt{witness-ebpf} uses...
See More →
Speakers
SS

Sanchit Sahay

Computer Science PhD student, New York University
Sanchit is a Computer Science PhD student at New York University's Secure Systems Lab where he works on software supply-chain security and operating systems research. Prior to NYU, he worked at Commvault Systems' Virtualization team securing private cloud infrastructure. Come say... Read More →
Tuesday October 6, 2026 17:20 - 17:38 CEST
South Hall 3A

17:35 CEST

Keynote: Closing Remarks - Steve Fernandez, OpenSSF Managing Director, The Linux Foundation
Tuesday October 6, 2026 17:35 - 17:40 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF General Manager, The Linux Foundation

Tuesday October 6, 2026 17:35 - 17:40 CEST
South Hall 3B
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.