Loading…
March 18-20, 2025
Napa, California
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for the event to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to find out more information.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

or to bookmark your favorites and sync them to your phone or calendar.
Venue: Vintner\'s Court clear filter
arrow_back View All Dates
Wednesday, March 19
 

9:00am PDT

Building New Open Source Standards - A Playbook for 2025 - Shane Coughlan, OpenChain Project
Wednesday March 19, 2025 9:00am - 9:30am PDT
The OpenChain Project has built two open source process management standards (ISO/IEC 5230 and ISO/IEC 18974) and deployed them across the open source supply chain. While OpenChain was the first Linux Foundation project in 14 years to produce an ISO standard, it is far from the last. During the 2023~2024 period, we saw growing engagement around Joint Development Foundation and committee discussions around standards or specifications in other LF projects. This talk will consolidate OpenChain's lessons learned in creating, submitting and deploying open source standards. It will help projects at any stage in the development lifecycle of specifications, including those only just considering this option for long-term impact. It will also help people with a specific interest in a more trusted supply chain to get more involved in OpenChain, building on our existing work or participating in new potential standards. Our optics will be on the legal, risk and compliance side due to the nature of the OpenChain Project's mission for a more trusted supply chain, but the core material will be equally applicable to technical, code or other projects working on this topic.
Speakers
avatar for Shane Coughlan

Shane Coughlan

General Manager, OpenChain Project
Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated OIN into the largest patent non-aggression community in history and establishing the first global network for open... Read More →
Wednesday March 19, 2025 9:00am - 9:30am PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any

10:00am PDT

Managing Open Source in an Age of Regulations - Nithya Ruff, Amazon
Wednesday March 19, 2025 10:00am - 10:30am PDT
Open Source today lives in an age of great scrutiny and regulations. The use of open source in mission critical applications and critical infrastructure means the bar is higher for security and quality. Governments around the world are putting regulations and policies in place to hold open source software to a higher bar. And OSPOs need to understand these regulations and focus on what they need to do to get the organization ready for them. I will discuss the role of the OSPO and what it can do to prepare their organizations and developers in this age of regulations.
Speakers
avatar for Nithya Ruff

Nithya Ruff

Director, Amazon OSPO, Amazon
Nithya is the Head of Amazon’s Open Source Program Office. Amazon’s customers value open source innovation and the cloud’s role in helping them adopt and run important open source services. She drives open source culture and coordination inside of Amazon and engagement with... Read More →
Wednesday March 19, 2025 10:00am - 10:30am PDT
Vintner's Court
  Legal / Compliance / Policy

10:45am PDT

Open Collaboration: Sustaining the Path To OSS Innovation in the Face of Rising Patent Threat - Keith Bergelt, Open Invention Network
Wednesday March 19, 2025 10:45am - 11:15am PDT
Open source software (OSS) has become a cornerstone of modern technological innovation. By allowing developers to collaborate and share code, OSS enables rapid progress and democratizes access to cutting-edge software. However, the very characteristics that make OSS so powerful—its openness, adaptability, and applicability—also make it a target for patent assertion entities (PAEs). These entities attempt to exploit the widespread adoption of common technologies across industries to extract patent settlements from businesses. The threat continues to grow as district court patent filings from PAEs grew by 14.1% in 2024, and are over half of all patent litigation cases.

Since 2005, Open Invention Network (OIN) has acted to safeguard OSS from patent risk through its patent cross-license in core OSS technologies. This session will provide information on the cross-license and case studies on how it has been used to successfully defend against PAEs.

This presentation will also discuss in detail efforts to protect OSS from PAEs by:
• collecting prior art and providing invalidity claim analyses
• supporting initiatives like the Open Source Zone, which has invalidated 50 NPE patents
Speakers
avatar for Keith Bergelt

Keith Bergelt

CEO, Open Invention Network
Keith Bergelt is the CEO of Open Invention Network (OIN), the largest patent non-aggression community in history, created to support freedom of action in Linux and adjacent open source technologies such as Kubernetes. Funded by Google, IBM/Red Hat, NEC, Philips, Sony, SUSE and Toyota... Read More →
Wednesday March 19, 2025 10:45am - 11:15am PDT
Vintner's Court
  Legal / Compliance / Policy

12:00pm PDT

Show Me What You Got: Turning SBOMs Into Actions - Georg Link, Bitergia & Brittany Istenes, Fannie Mae
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
Organizations that use open source software face risks related to licensing, security, and project health. Ensuring the sustainability of the open source ecosystem requires staying informed about compliance developments and achieving comprehensive visibility across activities. As the importance of Software Bill of Materials (SBOM) continues to grow, managing and utilizing this wealth of information effectively is becoming increasingly critical.

The goal is to equip application teams with tools that are both accessible and easy to manage while fostering strategic collaboration with internal risk partners, leadership, open source projects, open source contributions, and even vendors. Achieving scalable, efficient visibility into actual OSS usage is key.

So, how can organizations position themselves as proactive partners in this dynamic landscape? Join Georg Link and Brittany Istenes as they share practical strategies for navigating this complex ecosystem, empowering your organization to confidently and successfully leverage open source software.
Speakers
avatar for Georg Link

Georg Link

Open Source Strategist, Bitergia
Georg Link is an Open Source Strategist. Georg’s mission is to make open source more professional in its use of community metrics and analytics. Georg co-founded the Linux Foundation CHAOSS Project to advance analytics and metrics for open source project health. Georg is an active... Read More →
avatar for Brittany Istenes

Brittany Istenes

OSPO Strategist, Fannie Mae
Brittany Istenes started off her career as an elementary school educator which then led to a path of tech. Brittany has led advisory councils, special interest groups, open source contributions, community building, InnerSource initiatives and all the gray areas in between. At Fannie... Read More →
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
Vintner's Court
  Legal / Compliance / Policy

2:00pm PDT

How To Use Linux Foundation AI Frameworks for Regulation Compliance - Karen Bennet, Responsible AI Solutions
Wednesday March 19, 2025 2:00pm - 2:30pm PDT
In the rapidly evolving landscape of AI regulations, ensuring compliance with standards such as the EU AI Act, CRA (Cyber Resilience Act), ISO, and IEEE is paramount for organizations. The Linux Foundation's has a number of AI frameworks, such as the Model Openness Framework (MOF), Supply-chain Levels for Software Artifacts (SLSA), Responsible Generative AI Framework (RGAIF) and SPDX and Software Package Data Exchange (SPDX), which together provide a comprehensive approach to meeting
the needs of regulatory requirements. This talk demonstrates how these frameworks can be used to provide evidence of compliance,to enhance transparency, and ensure the security and integrity of AI systems.

By using these approaches, organizations can streamline their compliance processes, mitigate risks, and foster innovation. MOF ensures the openness and transparency of AI models, SLSA secures the software supply chain, RGAF guides organizations to embrace the ethical and intentional design, development and deployment of GAI solutions. Together, these tools offer a robust solution for navigating the complexities of AI regulations and standards.
Speakers
avatar for Karen Bennet

Karen Bennet

IEEE and ISO Officer, Responsible AI Solutions
Executive Director, Responsible AI Solutions, former executive of IBM, Red Hat and multiple AI startups, Co-Lead of Linux Foundation's SPDX AI and Dataset Profile Group, IEEE Vice Chair Technology and Society on AI Committee, officer on many ISO and IEEE AI Working groups, , Canadian... Read More →
Wednesday March 19, 2025 2:00pm - 2:30pm PDT
Vintner's Court
  Legal / Compliance / Policy

2:45pm PDT

Defining Open Source AI: Can the “Judgement of Solomon” Help the Open Source Community Find Success? - Jeffrey Borek, IBM Corporation
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
When faced with a difficult challenge sometimes it helps to look back at lessons from ancient history to guide your thinking. The Open Source Initiative (OSI) is working to create a definition for Open Source AI (OSAID), aiming to apply open source principles to artificial intelligence development, but clearly the 1.0 version is a work-in-progress. Can it find success? How may policy-makers react? Join this session to hear about the latest efforts to define open source AI and what's likely in store for 2025.
Speakers
avatar for Jeffrey Borek

Jeffrey Borek

WW Sr. Program Director, IBM Corporation
Working across IBM Research to build a scalable and consistent AI software supply chain security framework, while continuing to lead the consumption compliance Open Source Program Office (OSPO), including policy, execution and guidance. Working with IBM Government & Regulatory Affairs... Read More →
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Vintner's Court
  Legal / Compliance / Policy

3:45pm PDT

Catalyzing Open Source Projects at Academic Medical Centers: How and Why We Built the MGB License - Marvin Barksdale, Mass General Brigham - Innovation
Wednesday March 19, 2025 3:45pm - 4:15pm PDT
The modern Academic Medical Center ("AMC") has evolved beyond research & patient care to perform traditional commercial IP functions such as administration, licensing, and development, all in support of their central mission of the advancement of science and medicine. Aligned with this central mission is the proliferation of open-science research and open source innovation at AMCs, who have received millions of dollars from the US government in hopes of creating a flourishing ecosystem of collaboration. Unfortunately, at Mass General Brigham ("MGB") and other AMCs, open science and open source projects struggle to find fit in both licensing compliance and policy. Particularly for MGB, the largest recipient of NIH Open Science funding in the country, its commercial evolution and conservative licensing polices have combined to cause an open source licensing log jam. This session will review the competing AMC policy concerns that have caused MGB to disavow the use of most if not all osi approved licenses, and eventually lead to the development of their own permissive "open source" license.
Speakers
avatar for Marvin Barksdale

Marvin Barksdale

Associate Director, Business Development and Digital Health, Mass General Brigham - Innovation
Marvin Barksdale supports a range of system-wide business development activities at Mass General Brigham, focusing primarily on the commercialization of key and emerging discoveries, innovations, and other digital health technology. Leading the drafting, structuring, and negotiation... Read More →
Wednesday March 19, 2025 3:45pm - 4:15pm PDT
Vintner's Court
  Legal / Compliance / Policy

4:30pm PDT

Mission Possible: 24 Hours To Security Compliance - Philippe Ombredanne, AboutCode
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
CRA is coming. And this European regulation will impact software development worldwide. And your operations will be impacted.

You will have 24 hours to discover and disclose any relevant, critical vulnerabilities and notify security agencies.

Join Philippe Ombredanne to review which people, what processes, and technologies you will need to deploy by September 2026 to avoid large fines. We will share the latest development of the regulation implementation and how to work out minimalist and practical plans for compliance.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -