Loading…
March 18-20, 2025
Napa, California
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for the event to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to find out more information.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

or to bookmark your favorites and sync them to your phone or calendar.
Company: Any clear filter
arrow_back View All Dates
Wednesday, March 19
 

9:00am PDT

Building New Open Source Standards - A Playbook for 2025 - Shane Coughlan, OpenChain Project
Wednesday March 19, 2025 9:00am - 9:30am PDT
The OpenChain Project has built two open source process management standards (ISO/IEC 5230 and ISO/IEC 18974) and deployed them across the open source supply chain. While OpenChain was the first Linux Foundation project in 14 years to produce an ISO standard, it is far from the last. During the 2023~2024 period, we saw growing engagement around Joint Development Foundation and committee discussions around standards or specifications in other LF projects. This talk will consolidate OpenChain's lessons learned in creating, submitting and deploying open source standards. It will help projects at any stage in the development lifecycle of specifications, including those only just considering this option for long-term impact. It will also help people with a specific interest in a more trusted supply chain to get more involved in OpenChain, building on our existing work or participating in new potential standards. Our optics will be on the legal, risk and compliance side due to the nature of the OpenChain Project's mission for a more trusted supply chain, but the core material will be equally applicable to technical, code or other projects working on this topic.
Speakers
avatar for Shane Coughlan

Shane Coughlan

General Manager, OpenChain Project
Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated OIN into the largest patent non-aggression community in history and establishing the first global network for open... Read More →
Wednesday March 19, 2025 9:00am - 9:30am PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any

10:00am PDT

Accelerating Open Source Engagement: Insights from the State of Developer Adoption 2025 - Sean Lauer, Instruqt
Wednesday March 19, 2025 10:00am - 10:30am PDT
Open source software is at the heart of innovation, but its complexity often slows developer adoption, limiting impact. Developers need more than great technology—they need intuitive, hands-on experiences that empower them to truly engage.

Sean Lauer, VP of Marketing & Product, will share insights from The State of Developer Adoption 2025, a research report commissioned by Instruqt and conducted by Developer Marketing Alliance, exploring trends in developer enablement. Learn how leaders plan to turn complexity into opportunity—empowering developers, aligning goals, and fostering ecosystems that drive open source innovation.

Key takeaways for attendees:
• Strategic insights into overcoming adoption challenges and engaging developers with open source tools
• How to align open source project goals with organizational enablement strategies for long-term impact
• Emerging trends in developer engagement and the future of open source adoption
Speakers
avatar for Sean Lauer

Sean Lauer

Vice President, Marketing & Product, Instruqt
Sean Lauer, an award-winning marketer with over 16 years of experience, is the VP of Marketing & Product at Instruqt, a company redefining how software companies engage developers and drive adoption. Instruqt’s success reflects a deep understanding of modern computing and a passion... Read More →
Wednesday March 19, 2025 10:00am - 10:30am PDT
Silverado West

10:45am PDT

Developing a Foundation Strategy in an Uncertain World - Rebecca Rumbul, Rust Foundation
Wednesday March 19, 2025 10:45am - 11:15am PDT
This session will examine the importance of developing a strategy for maintenance, growth and development for OSS projects and foundations, and discuss the challenges in doing so. It will consider how to plan strategy development, how to ensure it is inclusive of the community and relevant stakeholders, how to ensure that key organisational and external aspects are considered, and how to track progress meaningfully towards success.
Speakers
avatar for Rebecca Rumbul

Rebecca Rumbul

CEO & Executive Director, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
Wednesday March 19, 2025 10:45am - 11:15am PDT
Silverado West

12:00pm PDT

The OSPO Has a New Sibling - AIO - Andrew Wafaa, Arm Ltd.
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
AI is everywhere now whether we like it or not. People want to use it in the workplace, but there are concerns about using this technology. Arm has established an AI Office (AIO) to give employees guidance on how they can use AI in their working lives as the world’s understandings evolve over license and copyright questions. As we stand on the brink of this transformative change, we must ask ourselves: are we ready to embrace the future and unlock the full potential of AI in our professional lives?
Speakers
avatar for Andrew Wafaa

Andrew Wafaa

Sr Director & Fellow, Arm Ltd.
Andrew leads Arm's Open Source Office as well as upstream interactions. He also sits on a number of industry and software bodies/projects including Yocto Project, FreeBSD Foundation, Xen, UXL Foundation, LF Edge & PyTorch Foundation
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
Silverado West
  OS Program Office (OSPO) / TODO Group
  • Audience Experience Level Any

2:45pm PDT

Take Control Over Your Project's CVE Entries Before Someone Else Does - Greg Kroah-Hartman, Linux Foundation
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Unless your project explicitly becomes a Certification Numbering Authority (CNA), it is possible for almost anyone else to create a random CVE entry against your project. With the upcoming responsibility that projects have due to laws like the CRA in Europe, it is getting more and more important for all open source projects to handle the tracking of security bugs and identifiers themselves, instead of assuming others will do it for them.

cve.org now allows all open source projects to be their own CNA, so there is no excuse not to take ownership of this for your project. Groups like curl, the Linux Kernel, Kubernetes, and Python have all done this already, and OpenSSF has produced information explaining how you too can do it.

This talk will go into why you want to become a CNA, the steps involved, and tips learned from the Linux kernel CVE team in handling their 8 CVEs issued a day, alone with other information about other country's numbering authorities which will be coming online in the next few years.
Speakers
avatar for Greg Kroah-Hartman

Greg Kroah-Hartman

Fellow, Linux Foundation
Greg Kroah-Hartman is a Fellow at the Linux Foundation. He is currently responsible for the stable Linux kernel releases, and a member of the Linux kernel CVE team. He is also a maintainer of the USB, TTY, and driver core subsystems in the kernel as well as other portions of the codebase... Read More →
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Silverado West

2:45pm PDT

Panel Discussion: Consumption Complacency: Bridging the Gap Between Discovery and Remediation - Brian Fox, Sonatype; Christopher Robinson, OpenSSF; Madison Oliver, GitHub
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Despite the availability of fixes for well-known vulnerabilities, open source software remains a significant target for attackers. In fact, three years after the infamous Log4j vulnerability, 13% of its downloads are still vulnerable. Even more concerning, 95% of vulnerable components downloaded today have a fixed version available.

In this session, Brian Fox (Sonatype), Christopher Robinson (OpenSSF), and Madison Oliver (GitHub) will explore these stark realities of open source vulnerabilities. The speakers will discuss why these vulnerabilities persist and how outdated or vulnerable components can slip through the cracks. Drawing from years of industry expertise, they will outline real-world remediation strategies and actionable best practices for mitigating open source risks.

Attendees will learn how to accelerate the adoption of secure components, integrate automated tools, and foster collaboration in the open source community to protect their software supply chain. Whether you’re a developer, security professional, or business leader, this session will equip you with the insights needed to secure your open source dependencies and strengthen your organization's resilience.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Brian Fox

Brian Fox

Co-founder and CTO, Sonatype
Co-founder and CTO, Brian Fox is an OpenSSF Governing Board member, a member of the Apache Software Foundation and former Chair of the Apache Maven project. As a direct contributor to the Maven ecosystem, including the maven-dependency-plugin and maven-enforcer-plugin, he has over... Read More →
avatar for Madison Oliver

Madison Oliver

Senior Security Manager, Advisory Database Curation, GitHub
Madison Oliver, vulnerability transparency advocate and senior security manager at GitHub, leads the advisory database team. Passionate about vulnerability reporting, response and disclosure, she co-chairs the relevant OpenSSF working group and serves on the CVE Program Board. Previously... Read More →
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Silverado East

4:30pm PDT

Mission Possible: 24 Hours To Security Compliance - Philippe Ombredanne, AboutCode
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
CRA is coming. And this European regulation will impact software development worldwide. And your operations will be impacted.

You will have 24 hours to discover and disclose any relevant, critical vulnerabilities and notify security agencies.

Join Philippe Ombredanne to review which people, what processes, and technologies you will need to deploy by September 2026 to avoid large fines. We will share the latest development of the regulation implementation and how to work out minimalist and practical plans for compliance.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -