
-
10:30 • SCORED Opening Remarks
-
10:40 • Ghost In The Codebase - Why Your LLM Needs a SCA/SAST Babysitter - Luca Galli, Open Systems AG
-
11:02 • The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort - Aleksandr Churilov, Independent Researcher
-
11:22 • SandScope: A Behavioral Audit Layer for MCP Tools in LLM Agent Supply Chains - Zhuoran Tan, University of Glasgow
-
11:42 • Librarian Catches Thief: Surfacing Supply Chain Attack Campaigns via Document Similarity in an AI Agent Skill Registry - Gale Fagan, Brightflag
-
12:02 • When Models Meet Loaders: Deserialization Risk in Huggingface - Xiang (Shawn) Guo, Victoria University of Wellington
-
12:22 • SoK: What Software Supply Chain Security Can Learn from Decades of Physical Supply Chain Risk Management - Linus Kühl, FH Münster
-
13:55 • Canary in the Code Mine: Predictive Risk Scoring for Open-Source Supply Chain Security - Timothy Brennan, Raytheon
-
14:17 • No Snake Oil: Verifying Python Package Builds - Jens Dietrich, Victoria University of Wellington
-
14:37 • Hurry Up and Wait: Malware Detection Timelines and Minimum Release Age for npm - Dominic Tassio, University of Kansas
-
14:57 • Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source Forks With Global History Analysis - Romain Lefeuvre, IRISA, Inria
-
15:45 • Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations - Abhishek Reddypalle, Purdue University & Dennis Roellke, Bloomberg
-
16:04 • When Dependencies Become Lemons: A Multivocal Review of Cheap Trust Signal Collapse in the Software Supply Chain - Ranindya Paramitha, North Carolina State University
-
16:23 • Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation - Aman Sharma, KTH Royal Institute of Technology
-
16:42 • When SBOMs Differ: A Large-Scale Empirical Study of Generation, Dependency Structure, and Regulatory Alignment - Lukas Gehrke, Technical University of Munich
-
17:01 • Mind the Gap: How SBOM Specification Ambiguities Lead to Divergent Software Bills of Materials. An Empirical Tool Study - Philippe Boinot, ANSSI; Olivier Zendra & Alan Prado, Inria Rennes
-
17:20 • Over the Shoulder: Improving SBOM Accuracy by Watching the Build - Sanchit Sahay, New York University
-
09:00 • Keynote: Welcome & Opening Remarks - Steve Fernandez, OpenSSF General Manager, The Linux Foundation
-
09:10 • Keynote Sessions To Be Announced
-
09:25 • Keynote: Who Funds the Toolchain? Secure Infrastructure for GLIBC and the GNU Toolchain - Kris Borchers, Senior Technical Program Manager, OpenSSF & Carlos O'Donell, Distinguished Engineer, Red Hat
-
09:45 • Keynote Sessions To Be Announced
-
10:30 • Who Pays When Debug Breaks? Supply-Chain Liability Under the CRA and the Product Liability Directive - Annika Kristin Niemann, iRights.Law Rechtsanwälte
-
10:55 • Preparing for the Vulnpocalypse: Using OSS-CRS To Find and Fix Bugs Before They Find You - Jeff Diecks, OpenSSF; Laura Guazzelli, Linux Foundation & Andrew Chin, Georgia Institute of Technology
-
11:20 • Defending Bare-Metal: Lessons Learnt From AI Security Analysis of Metal3 and OpenStack Ironic - Dmitry Tantsur, Red Hat & Tuomo Tanskanen, Ericsson Software Technology
-
11:45 • From First PR To Hardening Guide: Structured Security With Gemara - Hannah Braswell, Red Hat
-
12:05 • The SLSA Tooling Cake - Adolfo García Veytia, Carabiner Systems
-
12:25 • One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
-
13:55 • Operationalizing the CRA and Shaping OpenSSF’s Community Roadmap - Roman Zhukov, Red Hat; Daniel Appelquist, Samsung Electronics; Madalin Neag, OpenSSF; Megan Knight, Arm
-
14:30 • GAME SHOW!! GAME SHOW!! Part Dva!! - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
-
14:55 • When Maintainers Move On: Detecting and Communicating Abandoned Open-source Projects - Felix Lange, SAP SE
-
15:45 • The Kernel Does Not Negotiate: Building the Tooling To Say No To AI Agents - Sal Kimmich, NoLabs
-
16:10 • Verifiable AI Provenance: Closing the Attestation Gap in the Machine Learning Supply Chain - Sheng Sun, Dell & Sarah Evans, Dell Technologies
-
16:30 • Applying VEX To Vulnerability Information Sharing in Multi-tier Automotive Supply Chains - Yuta Kiyoumi, Honda Motor Co., Ltd. & Akihiko Takahashi, Fujitsu
-
16:50 • Securing Africas Open Source Ecosysetm: Community Health, Building Trust, Resilient, Sustainable Software - Ejiro Oghenekome, Independent; Victoria Ottah, Accessibility Nigeria ; Sal Kimmich, NoLabs; Christopher Robinson, OpenSSF; Amir Montazery, OSTIF
-
17:20 • SBOMs Are Useless Without Discoverability - Mario Fahlandt & Koray Oksay, Kubermatic
-
17:35 • Keynote: Closing Remarks - Steve Fernandez, OpenSSF Managing Director, The Linux Foundation