Loading…
Venue: South Hall 3B clear filter
Tuesday, October 6
 

09:00 CEST

Keynote: Welcome & Opening Remarks - Steve Fernandez, OpenSSF General Manager, The Linux Foundation
Tuesday October 6, 2026 09:00 - 09:10 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF General Manager, The Linux Foundation

Tuesday October 6, 2026 09:00 - 09:10 CEST
South Hall 3B

09:10 CEST

Keynote Sessions To Be Announced
Tuesday October 6, 2026 09:10 - 09:25 CEST

Tuesday October 6, 2026 09:10 - 09:25 CEST
South Hall 3B

09:25 CEST

Keynote: Who Funds the Toolchain? Secure Infrastructure for GLIBC and the GNU Toolchain - Kris Borchers, Senior Technical Program Manager, OpenSSF & Carlos O'Donell, Distinguished Engineer, Red Hat
Tuesday October 6, 2026 09:25 - 09:40 CEST
The GNU toolchain sits underneath a huge amount of the software the world relies on. GLIBC is a good place to start that conversation because so much depends on it, yet the systems behind projects like this often get far less attention than the code itself.

This keynote looks at why secure, reliable project infrastructure has become part of the open source security conversation. Source control, mailing lists, mirrors, release workflows, and long-term operations are not background details when the software involved sits in the path of operating systems, cloud platforms, embedded devices, AI systems, and public services.

We will talk about the work behind Core Toolchain Infrastructure, why it matters for GLIBC and the broader GNU toolchain, and what it means for the people and organizations that depend on this work every day. We will also share an important update on CTI’s next phase.

Attendees will leave with a clearer view of the risks CTI is meant to reduce, why upstream support is a security investment, and how companies can help strengthen the toolchain before the next failure forces the conversation.
Speakers
avatar for Kris Borchers

Kris Borchers

Senior Technical Program Manager, OpenSSF

avatar for Carlos O'Donell

Carlos O'Donell

Distinguished Engineer, Red Hat
Leading a team of passionate and dedicated developer to enhance and develop core runtimes for Red Hat Enterprise Linux and the layered products and stacks.

Looking forward to advancing the state of free and open-source system libraries and tooling used by developers. Always interested in low-level aspects of software and hardware interaction and how they effect the system as a whole, including hardware, kernel and core library design... Read More →
Tuesday October 6, 2026 09:25 - 09:40 CEST
South Hall 3B

09:45 CEST

Keynote Sessions To Be Announced
Tuesday October 6, 2026 09:45 - 10:00 CEST

Tuesday October 6, 2026 09:45 - 10:00 CEST
South Hall 3B

10:30 CEST

Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann, iRights.Law Rechtsanwälte
Tuesday October 6, 2026 10:30 - 10:50 CEST
On 8 Sept 2025, one phishing email hijacked a maintainer's npm account and pushed malicious versions of chalk, debug and 16 other packages totalling 2.6B weekly downloads. When such a package breaks something that hurts someone, who pays?
Two EU laws finalised in 2024 shape the answer, the Product Liability Directive and the Cyber Resilience Act, and their duties phase in across 2026 and 2027. So we go hands-on: we take this real compromise and walk it, step by step, down the liability chain. The maintainer, it turns out, is the one the law works hardest to shield as non-commercial open source sits largely outside both regimes. The bill lands downstream, on the commercial manufacturer who ships debug inside a product. Under the PLD, a missing security update can itself be a defect, under strict liability. The CRA adds a second layer since it lays a duty on to manage exactly this kind of vulnerability - detect it, report it, patch it - backed by fines, while the "open-source steward" carries a lighter, fine-free load.
Speakers
avatar for Annika Kristin Niemann

Annika Kristin Niemann

Lawyer, iRights.Law
Annika Niemann is a solicitor specialising in IT law, with a focus on open source compliance, supporting companies in the legally compliant use of open source software across the supply chain. She advises on CRA and product liability questions, including how the EU's Cyber Resilience... Read More →
Tuesday October 6, 2026 10:30 - 10:50 CEST
South Hall 3B

10:55 CEST

Preparing for the Vulnpocalypse: Using OSS-CRS To Find and Fix Bugs Before They Find You - Jeff Diecks, OpenSSF; Laura Guazzelli, Linux Foundation & Andrew Chin, Georgia Institute of Technology
Tuesday October 6, 2026 10:55 - 11:15 CEST
The open source ecosystem faces a Vulnpocalypse as AI-driven vulnerability reports surge. While potentially beneficial for security long-term, the current volume threatens to overwhelm open source projects. Maintainers work at human speed, and each report requires careful attention, verification, and disclosure.

So we need machines to help fix what the machines are finding.

In this workshop.we will walk through OSS-CRS. It's an OpenSSF project that gives us a standard orchestration framework for Cyber Reasoning Systems (CRS) capable of finding, proving and patching vulnerabilities.

Beyond the technology, we examine critical best practices for CRS usage. This includes how to build community norms that respect a maintainer's time instead of just dumping more work on their plate.

Attendees will learn:
- The current trends of AI-generated reports and the impact on open source
- How to run OSS-CRS for bug finding and fixing.
- Best practices for responsible use of AI tools in CVD.
Speakers
avatar for Jeff Diecks

Jeff Diecks

Senior Technical Program Manager, OpenSSF
Jeff Diecks is a Senior Technical Program Manager at The Linux Foundation. He has more than two decades of experience in technology and communications with a diverse background in operations, project management and executive leadership. A participant in open source since 1999, he’s... Read More →
avatar for Laura Guazzelli

Laura Guazzelli

Security Architect - AI/ML/LLM/Agentic Systems, OpenSSF - Linux Foundation
Laura has experience helping engineering and product teams build security into the way they work. With a background spanning DevSecOps, CI/CD, platform security, and AI/ML governance, Laura focuses on people and processes behind security systems as much as the technology itself.
avatar for Andrew Chin

Andrew Chin

Ph.D. Student, Georgia Institute of Technology

Tuesday October 6, 2026 10:55 - 11:15 CEST
South Hall 3B

11:20 CEST

Defending Bare-Metal: Lessons Learnt From AI Security Analysis of Metal3 and OpenStack Ironic - Dmitry Tantsur, Red Hat & Tuomo Tanskanen, Ericsson Software Technology
Tuesday October 6, 2026 11:20 - 11:40 CEST
AI-powered vulnerability discovery is here, and in 2026 it is no longer a noise generator either. These pipelines offer a powerful way to uncover 0-days in almost any software project. However, they introduce a distinct challenge: FOSS maintainers are now drowning in reports that are increasingly complex to analyze, especially as low-hanging fruit is rapidly plucked.

In this session, maintainers and security team members from Metal3.io and OpenStack Ironic projects share how they used an AI-based vulnerability analysis tool to uncover hidden issues. This domain is often riddled with legacy drivers and requirements to support deprecated protocols, yet built on modern cloud-native architectures where a vulnerability proof is rarely an easily automated, executable crash. For project maintainers, we will share our candid analysis of the typical AI report shortcomings, what to look for in triage, and how to deal with the incoming flow without burning out.
Speakers
avatar for Dmitry Tantsur

Dmitry Tantsur

Senior Principal Software Engineer, Red Hat
Long-term Metal3 and Ironic developer, OpenShift Metal team lead. My point of expertise is bare-metal management and provisioning
avatar for Tuomo Tanskanen

Tuomo Tanskanen

Principal Security Developer, Ericsson Software Technology
Tuomo is a telecom software engineer with 20+ years of hands-on experience across major industry giants. With vast and versatile experience in product security, incident response, and penetration testing, he is currently a Principal Security Developer at Ericsson and is Maintainer... Read More →
Tuesday October 6, 2026 11:20 - 11:40 CEST
South Hall 3B

11:45 CEST

From First PR To Hardening Guide: Structured Security With Gemara - Hannah Braswell, Red Hat
Tuesday October 6, 2026 11:45 - 12:00 CEST
We've all been new contributors at some point. You know the learning curve - best practices established before your first PR, specs that have been evolving for years. Should PRs require 3 reviewers? Do I need MFA? What are the actual threats to this project? Contributors need a clear way to understand not just how to contribute, but how to contribute securely.

The OpenSSF Gemara Project provides a standardized model and tooling to help projects define capabilities, identify threats, and document the controls that prevent them, structured across a 7-layer architecture. For maintainers shipping open source into the EU under the Cyber Resilience Act, structured governance isn't optional.
Speakers
avatar for Hannah Braswell

Hannah Braswell

Associate Product Security Engineer, Red Hat, Inc.
Hannah is an Associate Product Security Engineer at Red Hat, focused on securing complex open-source systems. She holds a B.S. in Computer Engineering from NC State University. An active contributor to several OpenSSF projects and Working Groups, she serves as Community Manager for... Read More →
Tuesday October 6, 2026 11:45 - 12:00 CEST
South Hall 3B

12:05 CEST

The SLSA Tooling Cake - Adolfo García Veytia, Carabiner Systems
Tuesday October 6, 2026 12:05 - 12:20 CEST
Starting in 2025, the SLSA project overhauled the tool catalog it maintains, unveiling new libraries and utilities while sunsetting older repositories that were not maintained any longer.

The project has now overhauled the projects under the SLSA umbrella into a more coherent stack starting with the spec and definitions at the bottom all the way to community integrations at the top. This is what we call the SLSA Tooling Cake and it is filled in the middle with delicious developer tools and end-user CLI tools.

In this talk we'll go through each of the five layers of the cake understanding what each offers to different consumers types: tool designers, agents, developers, end users, integrators, ecosystem partners, etc

During the talk we will also show a brief demo of each of the CLI tools: onboarding a repo to SLSA Source, generating a build provenance attestation and verifying it with the new pluggable verifier. We will also see how the new conformance suite ensures the SLSA ecosystem produces compatible data.
Speakers
avatar for Adolfo Garcia Veytia

Adolfo Garcia Veytia

Founding Engineer, Carabiner Systems
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Tuesday October 6, 2026 12:05 - 12:20 CEST
South Hall 3B

12:25 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them.

The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the same problem: we're scanning and rescanning the same packages for the same (or similar) data.

That redundancy has real costs. Compute, maintainer time, and contributor energy spent on work that's already done is capacity not spent on expanding coverage, improving accuracy, or hardening infrastructure.

It's time to build together. This talk is a conversation about what it would look like to join forces on open software supply chain data, produced with open source tools and backed by open standards with shared infrastructure and aligned and unlocked datasets for wider usage. We'll explore where our data models overlap, where they diverge, and what collaboration would require, so we all can get sustainable, high-quality, and open supply chain data at ecosystem scale faster together.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Tuesday October 6, 2026 12:25 - 12:40 CEST
South Hall 3B

13:55 CEST

Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov, Red Hat; Daniel Appelquist, Samsung Electronics; Madalin Neag, OpenSSF; Megan Knight, Arm
Tuesday October 6, 2026 13:55 - 14:25 CEST
As of Sept 11, 2026, the EU CRA mandates short-window reporting for actively exploited vulnerabilities to ENISA. Yet, Linux Foundation research shows 66% of the ecosystem remains unprepared, risking expensive "private forking" traps.

Hosted by the OpenSSF Global Cyber Policy WG, this 75-minute interactive workshop shifts the conversation from abstract legal theory to operational realities a lot of us are facing right now. Following a short briefing, the core 1-hour session unites enterprise engineers, security officers, stewards, open source developers and layers in collaborative 3 breakouts to stress-test real-world CRA challenges. Topics include: governance, open source particularities and CRA personas across varying PDE classifications, as well as secure-by-design mandates, risk assessments, due diligence, SBOMs, vulnerability management and reporting obligations. We conclude with a 15-minute synthesis of mapping live insights directly to OpenSSF roadmap and our work for the upcoming quarters.

Whether you are an enterprise architect trying to keep your product compliant, a steward, or an upstream developer, this workshop offers to tackle your specific use cases.
Speakers
avatar for Dan Appelquist

Dan Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the OpenSSF Global Cyber Policy working group and also has been a member of the OpenSSF's... Read More →
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product... Read More →
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, The Linux Foundation

avatar for Megan Knight

Megan Knight

Director Software Communities, Arm
Megan Knight is the Director of Software Communities at Arm where she leads upstream engagements with open source communities. She holds many leadership positions with various communities including Advocacy Chair for the Yocto Project, OSPO Special Interest Group lead for UXL Foundation... Read More →
Tuesday October 6, 2026 13:55 - 14:25 CEST
South Hall 3B

14:30 CEST

GAME SHOW!! GAME SHOW!! Part Dva!! - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Tuesday October 6, 2026 14:30 - 14:50 CEST
Bringing the same energy of the hit game show enjoyed at the 2026 OpenSSF Community Day North America to share with the European community with all new questions and the same security fun.
Join the OpenSSF staff and community and pit your knowledge of our community against your peers in this interactive game that EVERYONE can play. Come be educated, informed, and entertained.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Chief Architect - OpenSSF, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

Chief of Staff, OpenSSF, The Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across a multitude of industries, including defense, heavy machinery... Read More →
Tuesday October 6, 2026 14:30 - 14:50 CEST
South Hall 3B

14:55 CEST

When Maintainers Move On: Detecting and Communicating Abandoned Open-source Projects - Felix Lange, SAP SE
Tuesday October 6, 2026 14:55 - 15:15 CEST
Like any other software, open-source projects may become unmaintained or abandoned over time for various reasons. Unlike commercial software, the end of support for open-source projects or versions is often not announced upfront but happens gradually, e.g. due to personal reasons on the maintainer’s side. For consumers, this raises the challenge of identifying abandoned open-source components in their supply chain, particularly at scale. Identifying forks that may help remedy the situation is complex as well. For maintainers, the question arises how to best communicate a project's maintenance status or the nature of a fork to consumers.

Within this talk, we discuss repository-based metrics that we’ve found helpful in identifying abandoned Java and JavaScript projects. We also discuss how existing dependency assessment tools, such as OpenSSF Scorecard, perform in identifying abandoned components and how this scoring could possibly be improved. The talk also outlines how package registries could help improve the situation and how maintainers could document fork information in a machine-readable format.
Speakers
avatar for Felix Lange

Felix Lange

Open Source Security Architect, SAP SE
Felix Lange is an open-source security architect at SAP focused on securing open-source consumption and contribution. In this role, he also contributes to SAP’s Secure Software Development and Operations Lifecycle. Over the past four years, he has focused on scoring dependencies... Read More →
Tuesday October 6, 2026 14:55 - 15:15 CEST
South Hall 3B

15:45 CEST

The Kernel Does Not Negotiate: Building the Tooling To Say No To AI Agents - Sal Kimmich, NoLabs
Tuesday October 6, 2026 15:45 - 16:05 CEST
We give agents our full filesystem permissions because that is how Unix works. We give them network access because they need to call APIs. We give them access to credentials and shell history not because they need any of it, but because we have not built the tooling to say: you can have this, but not that.

This talk is about building that tooling, shipping it, and being honest about what it does and does not solve.

nono enforces per-tool-call restrictions at the kernel level using Linux Landlock. Real credentials never exist inside the agent's execution context. The audit log is written by a process outside the sandbox that the agent cannot reach. The kernel does not negotiate. Once the sandbox is applied it is irreversible.

We show it working in production: Kubefence, a Red Hat Kubernetes NRI plugin, and the nono-py integration being merged into Microsoft's agent-governance-toolkit. The Secure Agentic Framework gives us a shared language for which attack classes this addresses. We will walk through that map carefully because an accurate map is needed for an agentic security model.
Speakers
avatar for Sal Kimmich

Sal Kimmich

Security Architect, nolabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
Tuesday October 6, 2026 15:45 - 16:05 CEST
South Hall 3B

16:10 CEST

Verifiable AI Provenance: Closing the Attestation Gap in the Machine Learning Supply Chain - Sheng Sun, Dell & Sarah Evans, Dell Technologies
Tuesday October 6, 2026 16:10 - 16:25 CEST
AI/ML models remain outside established provenance frameworks such as SLSA, in‑toto, and SBOMs, leaving deployments without hardware‑rooted origin, signed attestations, or a verifiable chain of custody. This talk presents practical results from implementing verifiable AI provenance in an operational MLOps pipeline and highlights four gaps: fragmented lineage, unverifiable training environments, unsigned model artifacts, and non‑tamper‑evident pipeline history. We show how existing components—Marquez for lineage, IETF RATS attestation for environment integrity, SLSA plus Sigstore/cosign for artifact provenance, and adapters binding OpenLineage/MLflow events into signed RATS tokens—compose into a unified, auditable chain of custody. End‑to‑end evaluation demonstrates attestation‑gated workflows, reproducible promotion decisions, and detection of unverified or mis‑ordered stages. The result is a practical reference architecture for cryptographically anchored AI provenance that extends supply‑chain security across the ML lifecycle.
Speakers
avatar for Sheng Sun

Sheng Sun

Consultant, Software Technologist, Dell
Sheng Sun is a cybersecurity architect and AI security researcher with expertise in wireless security, trusted computing, and verifiable AI. At Huawei and Dell, he contributed to IEEE 802.11 and Wi‑Fi Alliance efforts, including WPA3. His work now focuses on attestation, AI integrity... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah Evans is a Distinguished Engineer and security applied research program lead at Dell Technologies, driving technical innovation for secure business outcomes. She is a recognized leader focusing on extending secure operations and supply chain principles to securing AI and agentic... Read More →
Tuesday October 6, 2026 16:10 - 16:25 CEST
South Hall 3B

16:30 CEST

Applying VEX To Vulnerability Information Sharing in Multi-tier Automotive Supply Chains - Yuta Kiyoumi, Honda Motor Co., Ltd. & Akihiko Takahashi, Fujitsu
Tuesday October 6, 2026 16:30 - 16:45 CEST
Automotive software, including In-Vehicle Infotainment (IVI) systems, is developed through multi-tier supply chains involving OEMs, Tier-1 suppliers, and other stakeholders. Under automotive cybersecurity
regulations, OEMs bear responsibility for managing vulnerabilities across the entire supply chain, making the exchange and tracking of vulnerability impact assessments among suppliers a significant
challenge.

VEX has been identified as a promising mechanism that could distribute vulnerability impact assessments among suppliers in response to these challenges. Using IVI software development as a focus, we
verified whether suppliers at each tier can produce VEX documents for their own products, and whether those assessments can be transmitted and utilized through a multi-tier supply chain while preserving
their intended meaning.

In this session, we present practical design guidelines for applying VEX to multi-tier supply chains. We also introduce design and operational approaches that enable VEX-based vulnerability assessment
distribution across complex supply chains beyond the automotive domain.
Speakers
avatar for Yuta KIYOUMI

Yuta KIYOUMI

staff, HONDA MOTOR CO.,LTD.
Yuta Kiyoumi is the Security Architect for IVI software development at Honda Motor Co., Ltd. He also serves as a member of the Honda OSPO promoting secure OSS adoption, and participates as a member of the OpenSSF.
avatar for Akihiko Takahashi

Akihiko Takahashi

Member, Fujitsu Ltd
Linux distributors for Edge computing machines
Tuesday October 6, 2026 16:30 - 16:45 CEST
South Hall 3B

16:50 CEST

Securing Africas Open Source Ecosysetm: Community Health, Building Trust, Resilient, Sustainable Software - Ejiro Oghenekome, Independent; Victoria Ottah, Accessibility Nigeria ; Sal Kimmich, NoLabs; Christopher Robinson, OpenSSF; Amir Montazery, OSTIF
Tuesday October 6, 2026 16:50 - 17:15 CEST
Open source software powers much of Africa's digital infrastructure. Across the continent, communities are building new projects, maintaining existing ones, and adopting global technologies to accelerate innovation.
As adoption grows, so does the responsibility to secure the software supply chains these projects depend on. African organisations face limited cybersecurity resources, inconsistent funding, and uneven access to audits and tooling.
But security depends as much on the people maintaining a project as on the tools they use. OpenSSF Scorecard, OSPS Baseline, and audits only matter if contributors are available to act on the results. Someone has to review findings, fix vulnerabilities, and keep the project healthy.
This panel explores why community health is a security issue, and why contributor retention, trust, and sustainable maintainership are essential to software security.
Drawing on the OpenSSF Africa SIG, CHAOSS community-health metrics, and OSTIF's work supporting under-resourced projects, panelists will discuss practical ways to build resilient communities, use security guidance with limited resources, and strengthen Africa's open source ecosystem.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Chief Architect - OpenSSF, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Victoria Ottah

Victoria Ottah

Accessibility Lead/Maintainer, CHAOSS
Toria is a UX designer, global speaker, and recognized A11y Evangelist dedicated to digital inclusion. She co-wrote the first digital ethical accessibility book and conducts crucial accessibility audits.
As the founder of Accessibility Nigeria, a WomenTech Network Ambassador/Adv... Read More →
avatar for Sal Kimmich

Sal Kimmich

Security Architect, nolabs
Sal Kimmich is a Security Architect and AI Governance Consultant working at the intersection of open source security and agentic systems. They contribute to the Confidential Computing Consortium, OpenSSF, CHAOSS, and CNCF, with a focus on runtime enforcement and supply chain integrity... Read More →
avatar for Amir Montazery

Amir Montazery

Managing Director, Open Source Technology Improvement Fund, Inc (OSTIF)
Amir Montazery is the Managing Director and Cofounder of Open Source Technology Improvement Fund, Inc (OSTIF). OSTIF is a Chicago-based organization focused on directly helping open-source software projects improve their security posture. Amir comes from a background in Finance, IT... Read More →
avatar for Ejiro Oghenekome

Ejiro Oghenekome

Cybersecurity Analyst/Researcher, OpenSSF

Tuesday October 6, 2026 16:50 - 17:15 CEST
South Hall 3B

17:20 CEST

SBOMs Are Useless Without Discoverability - Mario Fahlandt & Koray Oksay, Kubermatic
Tuesday October 6, 2026 17:20 - 17:35 CEST
SBOM generation is a solved problem. Syft, Trivy, and many more tools spit them out by the thousands. But what happens next? In most enterprises: nothing. SBOMs land in a bucket or CI artifact, and nobody looks at them again. The real challenge isn't producing SBOMs; it's making them actionable at scale.

This talk introduces BOMHort, an open source Kubernetes-native platform for SBOM consumption, visualization, and governance. We focus on the problem every enterprise faces once compliance mandates SBOM production: how do you make thousands of SBOMs searchable, surface relevant vulnerabilities and license issues, and produce reports that security, legal, and engineering teams can all understand without being SPDX experts?

BOMHort ingests SPDX and CycloneDX SBOMs from S3-compatible storage, enriches them with OSV vulnerability data, enforces configurable license compliance policies, and applies VEX statements for false positive suppression. All of it runs through a dashboard that turns raw SBOM data into decisions. We share lessons from building BOMHort and from enterprises that learned the hard way: an SBOM nobody can read is just compliance theater.
Speakers
avatar for Mario Fahlandt

Mario Fahlandt

Customer Delivery Architect, Kubermatic
Mario Fahlandt is a CNCF Technical Oversight Committee member, SIG ContribEx co-chair, and Kubernetes AI Conformance subproject lead. He maintains cncf/sbom, the project generating SPDX SBOMs for every CNCF release, and created SeeBOM, an open-source SBOM governance platform now applying... Read More →
avatar for Koray Oksay

Koray Oksay

Consultant, Kubermatic
Koray works at Kubermatic as a Kubernetes Consultant and Trainer, helping companies on their cloud-native journey. Before that, Koray worked for startup and enterprise companies in the advertising, banking, and telecom industries as a SysAdmin, Application Admin, DevOps Engineer... Read More →
Tuesday October 6, 2026 17:20 - 17:35 CEST
South Hall 3B

17:35 CEST

Keynote: Closing Remarks - Steve Fernandez, OpenSSF Managing Director, The Linux Foundation
Tuesday October 6, 2026 17:35 - 17:40 CEST

Speakers
avatar for Steve Fernandez

Steve Fernandez

OpenSSF General Manager, The Linux Foundation

Tuesday October 6, 2026 17:35 - 17:40 CEST
South Hall 3B
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.