Loading…
June 26, 2025 | Denver, Co
Learn More and Register To Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for OpenSSF Community Day NA 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Daylight Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

Schedule is subject to change.
Type: 15-minute Sessions clear filter
Thursday, June 26
 

10:10am MDT

Bridging the Chasm: Filling the Security Knowledge Gap Between Academia and Industry - Michael Biocchi, Snyk
Thursday June 26, 2025 10:10am - 10:25am MDT
In the realm of higher education, security education often remains less prioritized against the expanding sophistication of cyber threats. This oversight engenders a stark skills gap, subsequently contributing to a notable workforce deficiency within the cyber security sector. Despite numerous institutions across Canada and the United States offering computer security courses, their exclusion from the mandatory graduation requisites further accentuates the problem. In this talk, you’ll learn about these gaps and how to best address them within your organization and the technical community at large.
Speakers
avatar for Michael Biocchi

Michael Biocchi

Senior Product Manager, Security Education, Snyk
Michael Biocchi has completed his PhD and received his Masters of Science as well as his Bachelor of Computer Science. He is a Certified Information Systems Security Professional (CISSP). Michael has taught in the education sector for 15+ years, teaching a variety of computer science... Read More →
Thursday June 26, 2025 10:10am - 10:25am MDT
Bluebird Ballroom 3B

10:10am MDT

Taming the Wild West of ML: Practical Model Signing With Sigstore on Kaggle - Mihai Maruseac, Google
Thursday June 26, 2025 10:10am - 10:25am MDT
The rapid evolution of LLMs and the ML field has ushered in remarkable progress, but also a new wave of security threats. Model poisoning, supply chain vulnerabilities, and the challenge of verifying model and data provenance are just a few of the risks we face.

We've developed an efficient solution to sign models with Sigstore, at scale. This talk explores the practical experience of integrating this solution into Kaggle, a leading platform for data science and machine learning. We’ll share our journey of implementing model signing, from initial design to overcoming technical hurdles, and the resulting impact on Kaggle's community and the broader ML ecosystem.

Attendees will learn about the benefits of model signing, the challenges of large-scale platform integration, and best practices for securing ML workflows. By sharing actionable insights, we aim to empower other model hubs to adopt similar solutions. Protecting the integrity of all ML models through widespread adoption will prevent a significant number of ML supply chain incidents.
Speakers
avatar for Mihai Maruseac

Mihai Maruseac

Staff SWE, Google
Mihai Maruseac is a member of Google Open Source Security team (GOSST), working on Supply Chain Security, specifically for ML, but also a GUAC maintainer. Before joining GOSST, Mihai created the TensorFlow Security team after joining Google, moving from a startup to incorporate Differential... Read More →
Thursday June 26, 2025 10:10am - 10:25am MDT
Bluebird Ballroom 3A

11:25am MDT

Trends and Insights from the Sigstore Ecosystem - Eve Martin-Jones & Hayden Blauzvern, Google
Thursday June 26, 2025 11:25am - 11:45am MDT
Dive into the Sigstore ecosystem and discover insights about digital signing practices!

Sigstore provides tooling and services to simplify signing and verification. Critically, it makes signatures transparent and publicly auditable to detect malicious behavior. With the increasing adoption of Sigstore within open source communities, this has led to a wealth of information about supply chain security. Using the data in Sigstore's public transparency log Rekor, we can glean insights about signing in open source.

This talk will provide a brief overview of Sigstore, explaining its core components and how it enables secure digital signing. We will explore trends in how open source communities and organizations are utilizing Sigstore for signing, and answer questions such as, "What is the most commonly used identity provider?", "Do we see signing occur uniformly across a day?", and "How prevalent is the use of short-lived certificates rather than self-managed keys?"

Finally, we will describe how to access and leverage this data to find your own insights about the Sigstore ecosystem and signing in supply chain security.
Speakers
avatar for Hayden Blauzvern

Hayden Blauzvern

Technical Lead Manager, Google
Hayden Blauzvern is a technical lead manager on Google’s Open Source Security Team, focused on making open-source software more secure through code signing and applied transparency. Hayden is a maintainer and the community chair on the Sigstore project.
avatar for Eve Martin-Jones

Eve Martin-Jones

Senior Software Engineer, Google
Eve is an engineer working on open source software security at Google. She lives in Australia, with her cat Mochi, who is surprisingly proficient at JavaScript. Between D&D campaigns, she can be found deciphering the Cargo dependency-resolution algorithm bug-for-bug, advocating for... Read More →
Thursday June 26, 2025 11:25am - 11:45am MDT
Bluebird Ballroom 3A

11:50am MDT

Democratizing Cloud Native Security: How CNAMM Drives Evidence-Based Maturity - Abdel Sy Fane, DevSecFlow
Thursday June 26, 2025 11:50am - 12:05pm MDT
In the complex landscape of cloud native security, organizations struggle to effectively measure and improve their security posture. The Cloud Native Assurance Maturity Model (CNAMM) is an open, community-driven framework that democratizes security best practices through evidence-based assessment across 8 critical business functions. Learn how this practical framework helps organizations of all sizes build security excellence, backed by real implementation success stories. We'll explore CNAMM's methodology, demonstrate its value through case studies, and show how the community can contribute to its evolution.
Speakers
avatar for Abdel Sy Fane

Abdel Sy Fane

CTO, DevSecFlow
Abdel Sy Fane is a visionary cybersecurity leader with over 15 years of experience transforming digital landscapes across healthcare, finance, technology, and government sectors. As CTO of DevSecFlow and Co-Founder/Executive Director of CyberSecurity NonProfit (CSNP), he leads initiatives... Read More →
Thursday June 26, 2025 11:50am - 12:05pm MDT
Bluebird Ballroom 3B

11:50am MDT

From Model To Trust: Building Upon Tamper-proof ML Metadata Records - Mihai Maruseac, Google & Eoin Wickens, HiddenLayer
Thursday June 26, 2025 11:50am - 12:05pm MDT
The integrity and provenance of machine learning models are critical for building trustworthy AI systems. While cryptographic signing protects many digital assets, a standardized approach for verifying model origins and ensuring they haven't been tampered with is still missing. We are addressing this gap by building upon the OpenSSF Model Signing project – a PKI-agnostic method for creating verifiable claims on bundles of ML artifacts. We show how this project can expand beyond just model signing to also cover datasets, and other associated files, recording all integrity information in a single manifest.

In fact, this can be used as a foundation layer upon which we can build useful AI supply-chain solutions, both in terms of security and in terms of reducing development costs. Imagine querying "What datasets were used to train this model?" or determining which models and agents have been trained on a poisoned dataset, even before these get deploy in production systems. This is all possible by merging model signing, model cards, SLSA and AI-BOM information and analyzing all this metadata using tools such as GUAC. Our talk lays the groundwork for such capabilities.
Speakers
avatar for Mihai Maruseac

Mihai Maruseac

Staff SWE, Google
Mihai Maruseac is a member of Google Open Source Security team (GOSST), working on Supply Chain Security, specifically for ML, but also a GUAC maintainer. Before joining GOSST, Mihai created the TensorFlow Security team after joining Google, moving from a startup to incorporate Differential... Read More →
avatar for Eoin Wickens

Eoin Wickens

Director of Threat Intelligence, HiddenLayer
Eoin Wickens is the Technical Research Director - Field at HiddenLayer, where he both researches and speaks about security for artificial intelligence and machine learning. He has previously worked in threat research, threat intelligence and malware reverse engineering and has been... Read More →
Thursday June 26, 2025 11:50am - 12:05pm MDT
Bluebird Ballroom 3A

12:10pm MDT

Predicting OSS Vulnerabilities Through Communication Analysis: A Work in Progress - Shlok Gilda, University of Florida
Thursday June 26, 2025 12:10pm - 12:25pm MDT
Open-source software security depends not only on code quality but also on the health and effectiveness of developer communication. This session presents ongoing research developing “FORCE” (Framework for Open-Source Risk and Community Evaluation), a novel framework for proactively assessing OSS project risk. We will analyze communication patterns (sentiment, toxicity, outrage, stance, and key discussion topics) within GitHub repositories, combined with contributor network analysis and vulnerability data. This session will detail the methodology for creating the “Temporal Health Score” (THS), a composite metric designed to provide early warnings of potential security risks. We will discuss how prior research in areas like subtle toxicity detection and behavioral analysis informs the design of FORCE. The session will emphasize the potential for actionable insights for OSS maintainers, including strategies for improving communication, fostering collaboration, and mitigating identified risks. We also seek community feedback on the framework and its potential applications.
Speakers
avatar for Shlok Gilda

Shlok Gilda

PhD Candidate, University of Florida
Shlok Gilda is a 5th year PhD Candidate at the University of Florida in the Natural Language Research & Culture (NLP&C) Lab, advised by Dr. Bonnie J. Dorr. His research interests span critical cybersecurity domains, including user privacy, identity and access management, and vulnerability... Read More →
Thursday June 26, 2025 12:10pm - 12:25pm MDT
Bluebird Ballroom 3A

12:10pm MDT

Securing Public Sector Supply Chains Is a Team Sport - Daniel Moch, Lockheed Martin
Thursday June 26, 2025 12:10pm - 12:25pm MDT
The security of the software supply chain has attracted a lot of attention in recent years, and with efforts like Software Bill of Materials, Vulnerability Exchange and in-toto, a lot of work is being done to advance the state of the art. Drawing on a blog post published earlier this year on the OpenSSF blog and recent work from across industry, this talk describes some of the challenges public sector organizations face as they try to manage their supply chain and how the OpenSSF, with the broader open source community, can help address them.
Speakers
avatar for Daniel Moch

Daniel Moch

Staff Software Engineer, Lockheed Martin
For over 20 years, Daniel has worked as a software engineer in the Defense and Aerospace industry. His experience ranges from embedded device drivers to large logistics and information systems. In recent years, he has focused on helping legacy programs adopt modern DevOps practices... Read More →
Thursday June 26, 2025 12:10pm - 12:25pm MDT
Bluebird Ballroom 3B

12:30pm MDT

Beyond the Bot: Building Secure and Resilient AI Agents With Open Source - Mihai Maruseac, Google & Sarah Evans, Dell Technologies
Thursday June 26, 2025 12:30pm - 12:45pm MDT
2025 is the year LLMs broke out of the chatbot box. AI agents can now plan, execute, and learn all on their own in complex environments. This evolution makes 2023 seem like the stone age of AI. But with great power comes great responsibility - and a whole new attack surface to worry about: agentic AI demands a robust security model.

This talk dives into the world of AI agents, exploring what they are, what they can do, and—crucially—how to secure them. We'll examine the open-source tools that are fueling this revolution, including LangChain, LangGraph, DSPy, and the growing ecosystem of knowledge graph technologies and APIs. These powerful tools present incredible opportunities, but their architectural choices also introduce unique security risks. We'll dissect some of these risks, such as prompt injection and data poisoning, as well as compromised dependencies and insecure API interactions.

Our aim is to provide a guide on how to build secure and resilient AI agents using open-source best practices, ensuring today’s intelligent creations don't become tomorrow's security nightmares.
Speakers
avatar for Mihai Maruseac

Mihai Maruseac

Staff SWE, Google
Mihai Maruseac is a member of Google Open Source Security team (GOSST), working on Supply Chain Security, specifically for ML, but also a GUAC maintainer. Before joining GOSST, Mihai created the TensorFlow Security team after joining Google, moving from a startup to incorporate Differential... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah is a security innovation researcher, leveraging diverse experiences as an IT and security practitioner to improve security by design in emerging technologies. Prior to Dell, Sarah has had roles at in the finance, defense, manufacturing and education industries. Sarah also contributes... Read More →
Thursday June 26, 2025 12:30pm - 12:45pm MDT
Bluebird Ballroom 3A

3:35pm MDT

PQC & Crypto Agility: Hybrid Certificates, Different Formats, and Migration Strategies - Sven Rajala, Keyfactor
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Sven will cover hybrid cryptography in the context of post-quantum cryptography (PQC), examining the reasoning behind hybrid systems and their role in ensuring interoperability during migration while strengthening security against quantum threats.

He will also discuss hybrid PKI, exploring various proposed standards, their advantages and drawbacks, and their practical applications. Additionally, he will outline different PKI migration paths, providing strategies tailored to diverse organizational needs.

As organizations and solutions navigate the quantum horizon, it is essential to consider their unique circumstances when planning for the transition.
Speakers
avatar for Sven Rajala

Sven Rajala

Senior Solution Engineer, Keyfactor
Sven Rajala is a cybersecurity geek with 17+ years of expertise in PKI, automating PKI/signing solutions, and mastering containers. Known for sharing insights on PKI, EJBCA, and DevSecOps through YouTube tutorials, KEYMASTER sessions (@KeyfactorCommunity), and forums, he often infuses... Read More →
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Bluebird Ballroom 3B

3:35pm MDT

Signing and Verifying Multi-architecture Containers With Sigstore - Natalie Somersall, Chainguard
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Multi-architecture containers are magical to use—but a bit arcane to work with. Why does `docker pull python:3` grab only one architecture? How can we verify that the signed one is in use? In this talk, I’ll demystify how the order of operations for container resolution works. We’ll then dive into OCI manifests, image layers, tags, and how those map to annotations like SBOMs, attestations, and signatures. Using this info, we'll map out a couple strategies on generating and verifying this information with Cosign regardless of the architecture we need to use. I’ll walk through real-world weirdness I’ve helped folks through managing multi-arch images at scale, including how some registries and pull-through caches behave unexpectedly. This talk is for folks who use containers daily but want to lay the foundation for their software supply chain security.
Speakers
avatar for Natalie Somersall

Natalie Somersall

Principal Field Engineer, Public Sector, Chainguard
Natalie is a principal solutions engineer at Chainguard serving the public sector market. She spent years designing, building, and leading complex systems in regulated environments at a major systems integrator, but has also taken her career in many other directions - including detours... Read More →
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Bluebird Ballroom 3A
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.