Loading…
June 26, 2025 | Denver, Co
Learn More and Register To Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for OpenSSF Community Day NA 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Daylight Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

Schedule is subject to change.
Type: 10-minute Sessions clear filter
Thursday, June 26
 

10:55am MDT

A Dashboard for Actionable OpenSSF Scorecard Insights - Tracy Ragan, DeployHub, Inc.
Thursday June 26, 2025 10:55am - 11:05am MDT
OpenSSF Scorecard is a powerful tool for assessing the security health of open-source projects. However, making sense of its vast data and prioritizing improvements can be challenging. This presentation introduces a dashboard designed to visualize and streamline Scorecard insights, providing maintainers and security teams with a clear, actionable view of their project's security posture. Attendees will learn about Ortelius, a CDF Project, that has delivered a dashboard that aggregates key Scorecard metrics, tracking progress over time, and integrates with CI/CD pipelines to enhance automation. By the end of the session, participants will understand how this dashboard can help improve security practices, reduce vulnerabilities, and ensure compliance with industry best practices.
Speakers
avatar for Tracy Ragan

Tracy Ragan

CEO, DeployHub, Inc.
Tracy is a recognized expert in software supply chain security and DevSecOps, specializing in managing complex, decoupled architectures. She is the CEO of DeployHub, a scalable continuous vulnerability management platform that empowers software to 'self-heal' by automatically applying... Read More →
Thursday June 26, 2025 10:55am - 11:05am MDT
Bluebird Ballroom 3B

10:55am MDT

Myths Developers Believe About Open Source Security - Jess Lowe & Tim Zhang, Google
Thursday June 26, 2025 10:55am - 11:05am MDT
Forget what you think you know about immutable tags, perfect dependency graphs, and those supposedly foolproof lock files. We'll get down to the nitty-gritty of open source security, giving you real-world insights to keep your projects safe. For example, did you know that one package url (or “purl”) can map to many different packages? Trying to find consistency in cross-ecosystem names and identifiers is a hard problem! And how can we meaningfully report vulnerabilities if we don’t even have a consistent way to identify packages?

We can talk about vulnerabilities in transitive dependencies, but what even are your dependencies? A package doesn’t uniquely map to one set of dependencies – depending on your build flags or operating system, you can end up with arbitrarily many dependency graphs for one package.

We break open source security down to first principles by challenging the assumptions that we’ve all built upon, to hopefully resolve to a more consistent vision of the open source.

Number 5 will shock you!
Speakers
avatar for Jess Lowe

Jess Lowe

Software Engineer, Google
Jess is a Software Engineer in the Google Open Source Security Team working on OSV.dev and OSV-Scanner.
avatar for Tim Zhang

Tim Zhang

Engineer at Deps.dev, Google
A software engineer at Google. Relative newcomer to the field of securing the software supply chain.
Thursday June 26, 2025 10:55am - 11:05am MDT
Bluebird Ballroom 3A

12:30pm MDT

SWAG: Bringing Software Security Best Practices To the Web - Daniel Appelquist, Samsung
Thursday June 26, 2025 12:30pm - 12:40pm MDT
This session will be an overview of our efforts in the Secure Web Application Guidelines (SWAG) group, which has been working in coordination with the OpenSSF Best Practices group to develop security guidelines aimed at web developers. We'll go into some detail on the work and research that preceded this work and then talk about some of how this work differs from existing Best Practices, and how the the work of this group has influenced other sources for web developer documentation.
Speakers
avatar for Daniel Appelquist

Daniel Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the W3C Technical Architecture Group and is Co-Chair of OpenSSF's Global Cybersecurity... Read More →
Thursday June 26, 2025 12:30pm - 12:40pm MDT
Bluebird Ballroom 3B

2:40pm MDT

Evangelizing Security in India: Fears, Tears, and a Billion Deaf Ears - Ram Iyengar, Linux Foundation
Thursday June 26, 2025 2:40pm - 2:50pm MDT
This is a short session about my experiences in the past 18 months carrying the story of open source security across the length and breadth of India.
It is a geography that is just maturing in the IT spectrum, shifting from a predominantly services mindset to one of building products for the world.
This is a story of opportunities, of troubles, of tiresome evenings, and me questioning my life choices in airports as I battle flight delays and doom scrolling.
What does the country with the world’s largest developer population offer? A way forward? A threat of immaturity overpowering technical potential? A path to shape the developer mindset from the outset?
I don’t have all the answers. Maybe you do.
Speakers
avatar for Ram Iyengar

Ram Iyengar

Open Source Evangelist, Linux Foundation
Ram Iyengar is an engineer by practice and an educator at heart. He was (cf) pushed into technology evangelism along his journey as a developer and hasn’t looked back since! He enjoys helping engineering teams around the world discover new and creative ways to work. He is a proponent... Read More →
Thursday June 26, 2025 2:40pm - 2:50pm MDT
Bluebird Ballroom 3B

2:40pm MDT

The Open Source SDLC Control Plane: Building the Supply Chain Security Sandwich - Michael Lieberman, Kusari & Eman Abu Ishgair, Purdue
Thursday June 26, 2025 2:40pm - 2:50pm MDT
It seems like every day there’s a new security tool or best practice that emerges. At the same time developers are being asked to take on the burden of integrating all these tools and practices into their software development practices. These challenges mirror the problems developers and operators faced with the complexity of modern application operations that was eventually solved with technologies like kubernetes in the form of a container control plane. Come learn how a unified framework of software supply chain steps called AStRA can enable a new architecture in the form of a software development lifecycle (SDLC) control plane, to solve these problems and how building this might be simpler than you might think. OpenSSF has most of the pieces, they just need to be put together.
Speakers
avatar for Michael Lieberman

Michael Lieberman

CTO, Kusari
Michael Lieberman is co-founder and CTO of Kusari where he helps build transparency and security in the software supply chain. Michael is an active member of the open-source community, co-creating the GUAC and FRSCA projects and co-leading the CNCF’s Secure Software Factory Reference... Read More →
avatar for Eman Abu Ishgair

Eman Abu Ishgair

PhD Candidate in Electrical and Computer Engineering, Purdue
PhD candidate in ECE @ Purdue, working on software supply chain security
Thursday June 26, 2025 2:40pm - 2:50pm MDT
Bluebird Ballroom 3A

2:55pm MDT

Navigating Security in Generative AI Development - Katherine Druckman, Intel Corporation
Thursday June 26, 2025 2:55pm - 3:05pm MDT
As generative AI moves rapidly into production environments, developers face security challenges that traditional application security frameworks cannot fully address. This concise talk explores the fundamentals of AI security and compares how different communities—from security practitioners to AI researchers—are developing solutions through collaborative initiatives and open source communities and working groups.

Attendees will gain a clear understanding of how different communities, such as OpenSSF and OPEA and others, are addressing AI security challenges through complementary approaches, providing a foundation for implementing appropriate security controls in their own AI applications.

Topics Covered
* overview of AI security challenges vs traditional app sec
* Comparison of approaches from OpenSSF, OPEA Security Working Group, and other industry collaborations
Speakers
avatar for Katherine Druckman

Katherine Druckman

Open Source Evangelist, Intel Corporation
Katherine Druckman is an Open Source Evangelist at Intel, where she enjoys sharing her passion for a variety of open source topics. She currently combines her enthusiasm for software security and emerging AI technology as the OPEA Security Working Group Lead and Co-Chair of the OpenSSF... Read More →
Thursday June 26, 2025 2:55pm - 3:05pm MDT
Bluebird Ballroom 3A

2:55pm MDT

Simplifying SBOM Management: An Introduction To Bomctl - Allen Shearin & Ian Dunbar-Hall, Lockheed Martin
Thursday June 26, 2025 2:55pm - 3:05pm MDT
Bomctl is a new OpenSSF sandbox project designed to bridge the gap between SBOM generation and analysis. Leveraging the flexible and powerful expression of the Protobom library, bomctl
is natively format-agnostic, allowing effortless interaction with various SBOM formats. Bomctl enables the creation of to build a reference graph of SBOM documents and software packages, accurately representing modern software systems. With bomctl, data can be seamlessly pulled from SBOM generation tools and Source Code Management (SCM) platforms, and then pushed to SBOM registries, SCM platforms, and vulnerability analysis tools, streamlining your SBOM management workflow.
Speakers
avatar for Allen Shearin

Allen Shearin

Senior Full Stack Engineer, Lockheed Martin
Lockheed Martin Software Factory, Secure Software Supply Chain Team, Open Source Ecosystem Team. Active with a few OpenSSF projects, maintainer of bomctl.
avatar for Ian Dunbar-Hall

Ian Dunbar-Hall

Open Source Program Office, Lockheed Martin
Ian is a holds the position of Chief Engineer for Lockheed Martin Software Factory and specializes in DevSecOps and full stack engineering. Additionally he is a maintainer on SBOMit and an OpenSSF Governing Board General Member Representative.
Thursday June 26, 2025 2:55pm - 3:05pm MDT
Bluebird Ballroom 3B
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.