Loading…
March 18-20, 2025
Napa, California
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for the event to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to find out more information.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

or to bookmark your favorites and sync them to your phone or calendar.
Venue: Vintner\'s Court clear filter
Wednesday, March 19
 

9:00am PDT

Building New Open Source Standards - A Playbook for 2025 - Shane Coughlan, OpenChain Project
Wednesday March 19, 2025 9:00am - 9:30am PDT
The OpenChain Project has built two open source process management standards (ISO/IEC 5230 and ISO/IEC 18974) and deployed them across the open source supply chain. While OpenChain was the first Linux Foundation project in 14 years to produce an ISO standard, it is far from the last. During the 2023~2024 period, we saw growing engagement around Joint Development Foundation and committee discussions around standards or specifications in other LF projects. This talk will consolidate OpenChain's lessons learned in creating, submitting and deploying open source standards. It will help projects at any stage in the development lifecycle of specifications, including those only just considering this option for long-term impact. It will also help people with a specific interest in a more trusted supply chain to get more involved in OpenChain, building on our existing work or participating in new potential standards. Our optics will be on the legal, risk and compliance side due to the nature of the OpenChain Project's mission for a more trusted supply chain, but the core material will be equally applicable to technical, code or other projects working on this topic.
Speakers
avatar for Shane Coughlan

Shane Coughlan

General Manager, OpenChain Project
Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated OIN into the largest patent non-aggression community in history and establishing the first global network for open... Read More →
Wednesday March 19, 2025 9:00am - 9:30am PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any

10:00am PDT

Managing Open Source in an Age of Regulations - Nithya Ruff, Amazon
Wednesday March 19, 2025 10:00am - 10:30am PDT
Open Source today lives in an age of great scrutiny and regulations. The use of open source in mission critical applications and critical infrastructure means the bar is higher for security and quality. Governments around the world are putting regulations and policies in place to hold open source software to a higher bar. And OSPOs need to understand these regulations and focus on what they need to do to get the organization ready for them. I will discuss the role of the OSPO and what it can do to prepare their organizations and developers in this age of regulations.
Speakers
avatar for Nithya Ruff

Nithya Ruff

Director, Amazon OSPO, Amazon
Nithya is the Head of Amazon’s Open Source Program Office. Amazon’s customers value open source innovation and the cloud’s role in helping them adopt and run important open source services. She drives open source culture and coordination inside of Amazon and engagement with... Read More →
Wednesday March 19, 2025 10:00am - 10:30am PDT
Vintner's Court
  Legal / Compliance / Policy

10:45am PDT

Open Collaboration: Sustaining the Path To OSS Innovation in the Face of Rising Patent Threat - Keith Bergelt, Open Invention Network
Wednesday March 19, 2025 10:45am - 11:15am PDT
Open source software (OSS) has become a cornerstone of modern technological innovation. By allowing developers to collaborate and share code, OSS enables rapid progress and democratizes access to cutting-edge software. However, the very characteristics that make OSS so powerful—its openness, adaptability, and applicability—also make it a target for patent assertion entities (PAEs). These entities attempt to exploit the widespread adoption of common technologies across industries to extract patent settlements from businesses. The threat continues to grow as district court patent filings from PAEs grew by 14.1% in 2024, and are over half of all patent litigation cases.

Since 2005, Open Invention Network (OIN) has acted to safeguard OSS from patent risk through its patent cross-license in core OSS technologies. This session will provide information on the cross-license and case studies on how it has been used to successfully defend against PAEs.

This presentation will also discuss in detail efforts to protect OSS from PAEs by:
• collecting prior art and providing invalidity claim analyses
• supporting initiatives like the Open Source Zone, which has invalidated 50 NPE patents
Speakers
avatar for Keith Bergelt

Keith Bergelt

CEO, Open Invention Network
Keith Bergelt is the CEO of Open Invention Network (OIN), the largest patent non-aggression community in history, created to support freedom of action in Linux and adjacent open source technologies such as Kubernetes. Funded by Google, IBM/Red Hat, NEC, Philips, Sony, SUSE and Toyota... Read More →
Wednesday March 19, 2025 10:45am - 11:15am PDT
Vintner's Court
  Legal / Compliance / Policy

12:00pm PDT

Show Me What You Got: Turning SBOMs Into Actions - Georg Link, Bitergia & Brittany Istenes, Fannie Mae
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
Organizations that use open source software face risks related to licensing, security, and project health. Ensuring the sustainability of the open source ecosystem requires staying informed about compliance developments and achieving comprehensive visibility across activities. As the importance of Software Bill of Materials (SBOM) continues to grow, managing and utilizing this wealth of information effectively is becoming increasingly critical.

The goal is to equip application teams with tools that are both accessible and easy to manage while fostering strategic collaboration with internal risk partners, leadership, open source projects, open source contributions, and even vendors. Achieving scalable, efficient visibility into actual OSS usage is key.

So, how can organizations position themselves as proactive partners in this dynamic landscape? Join Georg Link and Brittany Istenes as they share practical strategies for navigating this complex ecosystem, empowering your organization to confidently and successfully leverage open source software.
Speakers
avatar for Georg Link

Georg Link

Open Source Strategist, Bitergia
Georg Link is an Open Source Strategist. Georg’s mission is to make open source more professional in its use of community metrics and analytics. Georg co-founded the Linux Foundation CHAOSS Project to advance analytics and metrics for open source project health. Georg is an active... Read More →
avatar for Brittany Istenes

Brittany Istenes

OSPO Strategist, Fannie Mae
Brittany Istenes started off her career as an elementary school educator which then led to a path of tech. Brittany has led advisory councils, special interest groups, open source contributions, community building, InnerSource initiatives and all the gray areas in between. At Fannie... Read More →
Wednesday March 19, 2025 12:00pm - 12:30pm PDT
Vintner's Court
  Legal / Compliance / Policy

2:00pm PDT

How To Use Linux Foundation AI Frameworks for Regulation Compliance - Karen Bennet, Responsible AI Solutions
Wednesday March 19, 2025 2:00pm - 2:30pm PDT
In the rapidly evolving landscape of AI regulations, ensuring compliance with standards such as the EU AI Act, CRA (Cyber Resilience Act), ISO, and IEEE is paramount for organizations. The Linux Foundation's has a number of AI frameworks, such as the Model Openness Framework (MOF), Supply-chain Levels for Software Artifacts (SLSA), Responsible Generative AI Framework (RGAIF) and SPDX and Software Package Data Exchange (SPDX), which together provide a comprehensive approach to meeting
the needs of regulatory requirements. This talk demonstrates how these frameworks can be used to provide evidence of compliance,to enhance transparency, and ensure the security and integrity of AI systems.

By using these approaches, organizations can streamline their compliance processes, mitigate risks, and foster innovation. MOF ensures the openness and transparency of AI models, SLSA secures the software supply chain, RGAF guides organizations to embrace the ethical and intentional design, development and deployment of GAI solutions. Together, these tools offer a robust solution for navigating the complexities of AI regulations and standards.
Speakers
avatar for Karen Bennet

Karen Bennet

IEEE and ISO Officer, Responsible AI Solutions
Executive Director, Responsible AI Solutions, former executive of IBM, Red Hat and multiple AI startups, Co-Lead of Linux Foundation's SPDX AI and Dataset Profile Group, IEEE Vice Chair Technology and Society on AI Committee, officer on many ISO and IEEE AI Working groups, , Canadian... Read More →
Wednesday March 19, 2025 2:00pm - 2:30pm PDT
Vintner's Court
  Legal / Compliance / Policy

2:45pm PDT

Defining Open Source AI: Can the “Judgement of Solomon” Help the Open Source Community Find Success? - Jeffrey Borek, IBM Corporation
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
When faced with a difficult challenge sometimes it helps to look back at lessons from ancient history to guide your thinking. The Open Source Initiative (OSI) is working to create a definition for Open Source AI (OSAID), aiming to apply open source principles to artificial intelligence development, but clearly the 1.0 version is a work-in-progress. Can it find success? How may policy-makers react? Join this session to hear about the latest efforts to define open source AI and what's likely in store for 2025.
Speakers
avatar for Jeffrey Borek

Jeffrey Borek

WW Sr. Program Director, IBM Corporation
Working across IBM Research to build a scalable and consistent AI software supply chain security framework, while continuing to lead the consumption compliance Open Source Program Office (OSPO), including policy, execution and guidance. Working with IBM Government & Regulatory Affairs... Read More →
Wednesday March 19, 2025 2:45pm - 3:15pm PDT
Vintner's Court
  Legal / Compliance / Policy

3:45pm PDT

Catalyzing Open Source Projects at Academic Medical Centers: How and Why We Built the MGB License - Marvin Barksdale, Mass General Brigham - Innovation
Wednesday March 19, 2025 3:45pm - 4:15pm PDT
The modern Academic Medical Center ("AMC") has evolved beyond research & patient care to perform traditional commercial IP functions such as administration, licensing, and development, all in support of their central mission of the advancement of science and medicine. Aligned with this central mission is the proliferation of open-science research and open source innovation at AMCs, who have received millions of dollars from the US government in hopes of creating a flourishing ecosystem of collaboration. Unfortunately, at Mass General Brigham ("MGB") and other AMCs, open science and open source projects struggle to find fit in both licensing compliance and policy. Particularly for MGB, the largest recipient of NIH Open Science funding in the country, its commercial evolution and conservative licensing polices have combined to cause an open source licensing log jam. This session will review the competing AMC policy concerns that have caused MGB to disavow the use of most if not all osi approved licenses, and eventually lead to the development of their own permissive "open source" license.
Speakers
avatar for Marvin Barksdale

Marvin Barksdale

Associate Director, Business Development and Digital Health, Mass General Brigham - Innovation
Marvin Barksdale supports a range of system-wide business development activities at Mass General Brigham, focusing primarily on the commercialization of key and emerging discoveries, innovations, and other digital health technology. Leading the drafting, structuring, and negotiation... Read More →
Wednesday March 19, 2025 3:45pm - 4:15pm PDT
Vintner's Court
  Legal / Compliance / Policy

4:30pm PDT

Mission Possible: 24 Hours To Security Compliance - Philippe Ombredanne, AboutCode
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
CRA is coming. And this European regulation will impact software development worldwide. And your operations will be impacted.

You will have 24 hours to discover and disclose any relevant, critical vulnerabilities and notify security agencies.

Join Philippe Ombredanne to review which people, what processes, and technologies you will need to deploy by September 2026 to avoid large fines. We will share the latest development of the regulation implementation and how to work out minimalist and practical plans for compliance.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
Wednesday March 19, 2025 4:30pm - 5:00pm PDT
Vintner's Court
  Legal / Compliance / Policy
  • Audience Experience Level Any
 
Thursday, March 20
 

10:00am PDT

Understanding and Managing SBOMs in Modern Automotive Vehicles: A Journey - Yuichi Kusakabe & Takashi Ninjouji, Honda Motor Co., Ltd.
Thursday March 20, 2025 10:00am - 10:30am PDT
The SBOM (Software Bill of Materials) for a single automotive vehicle is in high demand. Modern vehicles are advanced information systems that constantly evolve, with frequently changing software configurations. This trend is even more pronounced in Software Defined Vehicles (SDVs). Open source supports this evolution. Understanding the software components that make up a vehicle is crucial for asset and risk management, making it a valuable endeavor in the software supply chain. The introduction of process management standards like ISO 5230 and ISO 18974, and the adoption of standard data formats through SPDX Lite (ISO 5962 (SPDX 2.2.1) and the annex of SPDX 2.3), are expected to yield significant results. Meanwhile, there is growing interest in more effective SBOM content and how to share and handle this information. In this session, we will share insights and challenges gained through the development of IVI.
Speakers
avatar for Yuichi Kusakabe

Yuichi Kusakabe

Chief Architect / OSPO Tech Lead, Honda Motor Co., Ltd.
Yuichi Kusakabe is the Chief Architect at Honda Motor Co., Ltd. , AGL(Automotive Grade Linux) member and COVESA(Connected Vehicle Systems Alliance) member since 2011 with over twenty years of Automotive and Open Source Software Experience.Prior to joining Honda Motor he worked for... Read More →
avatar for Takashi Ninjouji

Takashi Ninjouji

Chief Engineer, Honda Motor Co., Ltd.
Takashi Ninjouji, Chief Engineer at Honda Motor Co., Ltd., focuses on Software-Defined Vehicle (SDV) and the Open Source Program Office (OSPO). His interests also include Security Assurance and SBOM. He spent 10 years in Telecom and Mobile industries working on R&D. For the past 15... Read More →
Thursday March 20, 2025 10:00am - 10:30am PDT
Vintner's Court
  OS Program Office (OSPO) / TODO Group
  • Audience Experience Level Any

10:45am PDT

Teaching Open Source Risk and Investment: A Framework - Emma Irwin, Microsoft
Thursday March 20, 2025 10:45am - 11:15am PDT
Microsoft's Open Source Programs Office (OSPO) has been building tools and resources to increase visibility of risk according to a set of metrics (Rubrics) in our open source dependencies.

Like many things open source, the path to resolving risk through investment, is a 'learn by doing' exercise. Simply saying 'this project needs funds' isn't helpful to decision makers. What *is*helpful is being able to describe risk, who shares that risk, and what type of investment is most likely to have impact (and ways of tracking that investment over time).

In this talk, I'll share with you our new learn by doing 'investing in open source dependencies framework' to help those advocating for funding, build business cases to advocate strategically for those outcomes. I'll also share a couple of case studies to show how it might work in your company.

We’re learning here too, and look forward to expanding some of the ways we can experiment together and empower every employee to advocate for the need that they see in their dependencies to ultimately contribute to a more secure healthy ecosystem.
Speakers
avatar for Emma Irwin

Emma Irwin

Principal TPM, Microsoft
Emma Irwin has been working in open source for nearly 20 years. She is currently a Principal TPM on Microsoft's OSPO - living and working in Sooke BC.
Thursday March 20, 2025 10:45am - 11:15am PDT
Vintner's Court

12:00pm PDT

TODO Steering Committee - Management & OSPO Ask Anything - Brittany Istenes, Fannie Mae
Thursday March 20, 2025 12:00pm - 12:30pm PDT
This Ask Me Anything session connects attendees to the TODO Group Steering Committee. The TODO Group is an open community of practitioners who aim to create, share knowledge and collaborate on best practices on open source management in organizations to run successful Open Source Program Offices.

Members of the steering committee will assist the audience through the best practices, guides, and tools made by and for open source managers to help them in their day-to-day responsibilities, as well as share their first-hand experiences and lessons learned in building and operating OSPOs. Additionally, attendees will learn ways to connect with the TODO Group – the largest OSPO community dedicated to building best practices in open source management. The session will also provide insights into what OSPOs are facing within the compliance and policy space as well as how people can partner with the ToDo Group.
Speakers
avatar for Brittany Istenes

Brittany Istenes

OSPO Strategist, Fannie Mae
Brittany Istenes started off her career as an elementary school educator which then led to a path of tech. Brittany has led advisory councils, special interest groups, open source contributions, community building, InnerSource initiatives and all the gray areas in between. At Fannie... Read More →
Thursday March 20, 2025 12:00pm - 12:30pm PDT
Vintner's Court

2:00pm PDT

Use OSS To Serve OSS - Ant OSPO's Trial Approach on Dev Tooling and OSPO Infra - Richard Sikang Bian & Florian Fan, Ant Group
Thursday March 20, 2025 2:00pm - 2:30pm PDT
Ant Group established its Open Source Program Office (OSPO) over three years ago, initially focused on compliance and project support. Over the years, the team has evolved into a full-fledged business unit with dedicated emphasis on strategy, growth, developer experience, and internationalization. As the team has matured, one key insight we've gained is the critical importance of development tooling and "OSPO infra" to systematically support our growing portfolio of more than 20 internal projects—a number that continues to expand.

Operating without dedicated developer or product resources, we have pioneered a unique approach to building and scaling our infrastructure. In this session, we will share our perspective for "OSPO infra" and the toolkit we've developed so far. We will also explore a specialized area of focus for Ant Group—graph technology—and how it plays a critical role in this initiative.

The second half of the presentation will delve into a case study demonstrating how our OSPO collaborates with the Graph team (https://github.com/tugraph-family) to build open-source tools that have proven valuable in supporting and serving OSS teams.
Speakers
avatar for Richard Sikang Bian

Richard Sikang Bian

Head of Open Source; Director of Product and Strategy (OSS), Ant Group
An ex-Square, ex-Microsoft engineer, Richard led Ant Group OSS from day 1 and developed the initiative into a cross-functional team covering governance, strategy, developer experience, product and growth efforts. We collaborate closely with 20+ internal teams to help their strategy... Read More →
avatar for Florian Fan

Florian Fan

TuGraph Open Source Lead, Ant Group
Florian Fan (范志东), Ant Group TuGraph Open Source Lead, Developer Relations Advocate, and TuGraph/DB-GPT/OSGraph Maintainer. He has worked for Tencent, Alibaba Cloud, and Ant Group, focusing on "Graph+AI" technology including Big Data, Databases, Graph Computing, Knowledge Graph... Read More →
Thursday March 20, 2025 2:00pm - 2:30pm PDT
Vintner's Court

3:45pm PDT

Enhancing Diversity and Inclusion in Open-Source Communities: Turning Strategy into Impact - Regina Nkenchor, GNOME Foundation
Thursday March 20, 2025 3:45pm - 4:15pm PDT
Research has shown that diversity is not just a buzzword but a critical factor that significantly impacts the effectiveness and success of open-source communities. Building an inclusive environment requires more than recognizing the importance of diversity; it demands concrete actions, tangible outcomes, and a genuine commitment to creating a welcoming space for all contributors. This talk draws from an in-depth study of the GNOME Project's diversity and inclusion strategies, examining the opportunities and challenges in fostering inclusiveness. By exploring these experiences, the aim of this talk is to provide actionable recommendations for improving diversity efforts.

While some open-source projects have implemented strategies to create a diverse and inclusive environment, they often struggle to achieve impactful outcomes. How can we move beyond setting diversity and inclusion strategies to achieve measurable results? Are policies and initiatives enough to foster true inclusiveness? In this talk, I will share recommended strategies to foster contributions from diverse groups.
Speakers
avatar for Regina Nkenchor

Regina Nkenchor

Project Maintainer and Community Director of GNOME Africa, GNOME Foundation
Regina is the Project Maintainer and Community Director of GNOME Africa, as well as a member of the Diversity & Inclusion Community. She served two terms as Vice President of the Board of Directors at the GNOME Foundation, where she played a pivotal role in shaping the project's diversity... Read More →
Thursday March 20, 2025 3:45pm - 4:15pm PDT
Vintner's Court

4:30pm PDT

Panel Discussion: Japan Evangelist Program - A Model To Foster Regional Communities - Noriaki Fukuyasu, The Linux Foundation; Yuichi Nakamura & Ayumi Watanabe, Hitachi; Masato Endo, Toyota Motor Corporation; & Munehiro Ikeda, Cybertrust Japan
Thursday March 20, 2025 4:30pm - 5:00pm PDT
Open source is everywhere. Anyone can use it and anyone can contribute codes to the community regardless of the countries and regions. It is inherently borderless.In the meantime, it is also true that most of the critical open source projects are English speaking communities. This actually creates a gap between English speaking regions and non-English speaking regions in terms of the knowledge about the technologies as well as opportunity to get involved in the community development. There has to be a “Bridge” to fill the gap.

The Linux Foundation Japan office launched a program to solve this issue by launching the Japan Evangelist Program, which has been a big success so far. The evangelists can also become a community by itself, they become a force to connect multiple communities to co-work to create larger values as well as sharing best practice to run meetup etc, which has been a nice side effect of the program.

In this session, through the discussion with the panelists (they are all Japan Evangelists) we would like to elaborate how the program is actually working.
Speakers
avatar for Munehiro Ikeda

Munehiro Ikeda

Lead Architect, Cybertrust Japan Co., Ltd.
Ikeda Munehiro is a key engineer in the IoT Technology Division at Cybertrust Japan, working on leading-edge technologies and contributing to the Open Source Security Foundations (OpenSSF) activities on OSS security and supply chain.
avatar for Noriaki Fukuyasu

Noriaki Fukuyasu

VP of Japan Operations, The Linux Foundation
VP of Japan Operations at Linux Foundation.
avatar for Masato Endo

Masato Endo

Project General Manager, Toyota Motor Corporation
Masato Endo is a Project General Manager of Value Chain Innovation Project in TOYOTA. He focuses also on promoting Open Source Innovation and he set up TOYOTA OSPO in 2024. Furthermore, he plays the following roles in Open Source Communities. -The Linux Foundation Japan Evangelist... Read More →
avatar for Yuichi Nakamura

Yuichi Nakamura

Head of OSPO, Hitachi,Ltd
Yuichi Nakamura, Ph.D has been engaged with OSS over 20 years, contributed to SELinux, given presentations in many OSS events such as Linux Security Summit, Embedded Linux Conference and KubeCon. He also launched ecosystem of business and OSS contribution model based on Keycloak in... Read More →
avatar for Ayumi Watanabe

Ayumi Watanabe

Senior OSS Specialist of Hitachi Solutions, Ltd., Hitachi Solutions, Ltd.
Ayumi Watanabe is a Senior OSS Specialist of Hitachi Solutions, Ltd.. She is also a core member of OpenChain Japan and known as a SBOM evangelist. Her strong point is a knowledge of many tools for SBOM generation and management, a wide range of experiences as an OSS management consultant... Read More →
Thursday March 20, 2025 4:30pm - 5:00pm PDT
Vintner's Court
  Global Collaboration and Diversity
  • Audience Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.