Loading…
June 26, 2025 | Denver, Co
Learn More and Register To Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for OpenSSF Community Day NA 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Daylight Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

Schedule is subject to change.
Venue: Bluebird Ballroom 3B clear filter
Thursday, June 26
 

10:10am MDT

Bridging the Chasm: Filling the Security Knowledge Gap Between Academia and Industry - Michael Biocchi, Snyk
Thursday June 26, 2025 10:10am - 10:25am MDT
In the realm of higher education, security education often remains less prioritized against the expanding sophistication of cyber threats. This oversight engenders a stark skills gap, subsequently contributing to a notable workforce deficiency within the cyber security sector. Despite numerous institutions across Canada and the United States offering computer security courses, their exclusion from the mandatory graduation requisites further accentuates the problem. In this talk, you’ll learn about these gaps and how to best address them within your organization and the technical community at large.
Speakers
avatar for Michael Biocchi

Michael Biocchi

Senior Product Manager, Security Education, Snyk
Michael Biocchi has completed his PhD and received his Masters of Science as well as his Bachelor of Computer Science. He is a Certified Information Systems Security Professional (CISSP). Michael has taught in the education sector for 15+ years, teaching a variety of computer science... Read More →
Thursday June 26, 2025 10:10am - 10:25am MDT
Bluebird Ballroom 3B

10:30am MDT

OSPS: All Your Base Are Belong To Us - Christopher Robinson, OpenSSF & Eddie Knight, Sonatype
Thursday June 26, 2025 10:30am - 10:50am MDT
Contributors and maintainers will benefit from increased visibility to changes in the ecosystem, especially as LFX Insights works to display Baseline results for all projects. The baseline is already fully adopted as a project requirement by the OpenSSF TAC, and adoption is underway by the FINOS and CNCF technical oversight committees. Past or Present Chairs from each of the three bodies are leading contributors to the effort.

End User members will benefit by better understanding the measures that Linux Foundation is taking to ensure that projects are being held to robust security standards.
Speakers
avatar for Eddie Knight

Eddie Knight

OSPO Lead, Sonatype
Eddie Knight is a Software and Cloud Engineer with a background in banking technology. When he isn’t playing with his 2-year-old son, he combines his passion and job duties by working to improve the security of open source software. Eddie helps lead CNCF's Security Technical Advisory... Read More →
Thursday June 26, 2025 10:30am - 10:50am MDT
Bluebird Ballroom 3B

10:55am MDT

A Dashboard for Actionable OpenSSF Scorecard Insights - Tracy Ragan, DeployHub, Inc.
Thursday June 26, 2025 10:55am - 11:05am MDT
OpenSSF Scorecard is a powerful tool for assessing the security health of open-source projects. However, making sense of its vast data and prioritizing improvements can be challenging. This presentation introduces a dashboard designed to visualize and streamline Scorecard insights, providing maintainers and security teams with a clear, actionable view of their project's security posture. Attendees will learn about Ortelius, a CDF Project, that has delivered a dashboard that aggregates key Scorecard metrics, tracking progress over time, and integrates with CI/CD pipelines to enhance automation. By the end of the session, participants will understand how this dashboard can help improve security practices, reduce vulnerabilities, and ensure compliance with industry best practices.
Speakers
avatar for Tracy Ragan

Tracy Ragan

CEO, DeployHub, Inc.
Tracy is a recognized expert in software supply chain security and DevSecOps, specializing in managing complex, decoupled architectures. She is the CEO of DeployHub, a scalable continuous vulnerability management platform that empowers software to 'self-heal' by automatically applying... Read More →
Thursday June 26, 2025 10:55am - 11:05am MDT
Bluebird Ballroom 3B

11:50am MDT

Democratizing Cloud Native Security: How CNAMM Drives Evidence-Based Maturity - Abdel Sy Fane, DevSecFlow
Thursday June 26, 2025 11:50am - 12:05pm MDT
In the complex landscape of cloud native security, organizations struggle to effectively measure and improve their security posture. The Cloud Native Assurance Maturity Model (CNAMM) is an open, community-driven framework that democratizes security best practices through evidence-based assessment across 8 critical business functions. Learn how this practical framework helps organizations of all sizes build security excellence, backed by real implementation success stories. We'll explore CNAMM's methodology, demonstrate its value through case studies, and show how the community can contribute to its evolution.
Speakers
avatar for Abdel Sy Fane

Abdel Sy Fane

CTO, DevSecFlow
Abdel Sy Fane is a visionary cybersecurity leader with over 15 years of experience transforming digital landscapes across healthcare, finance, technology, and government sectors. As CTO of DevSecFlow and Co-Founder/Executive Director of CyberSecurity NonProfit (CSNP), he leads initiatives... Read More →
Thursday June 26, 2025 11:50am - 12:05pm MDT
Bluebird Ballroom 3B

12:10pm MDT

Securing Public Sector Supply Chains Is a Team Sport - Daniel Moch, Lockheed Martin
Thursday June 26, 2025 12:10pm - 12:25pm MDT
The security of the software supply chain has attracted a lot of attention in recent years, and with efforts like Software Bill of Materials, Vulnerability Exchange and in-toto, a lot of work is being done to advance the state of the art. Drawing on a blog post published earlier this year on the OpenSSF blog and recent work from across industry, this talk describes some of the challenges public sector organizations face as they try to manage their supply chain and how the OpenSSF, with the broader open source community, can help address them.
Speakers
avatar for Daniel Moch

Daniel Moch

Staff Software Engineer, Lockheed Martin
For over 20 years, Daniel has worked as a software engineer in the Defense and Aerospace industry. His experience ranges from embedded device drivers to large logistics and information systems. In recent years, he has focused on helping legacy programs adopt modern DevOps practices... Read More →
Thursday June 26, 2025 12:10pm - 12:25pm MDT
Bluebird Ballroom 3B

12:30pm MDT

SWAG: Bringing Software Security Best Practices To the Web - Daniel Appelquist, Samsung
Thursday June 26, 2025 12:30pm - 12:40pm MDT
This session will be an overview of our efforts in the Secure Web Application Guidelines (SWAG) group, which has been working in coordination with the OpenSSF Best Practices group to develop security guidelines aimed at web developers. We'll go into some detail on the work and research that preceded this work and then talk about some of how this work differs from existing Best Practices, and how the the work of this group has influenced other sources for web developer documentation.
Speakers
avatar for Daniel Appelquist

Daniel Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He is co-chair of the W3C Technical Architecture Group and is Co-Chair of OpenSSF's Global Cybersecurity... Read More →
Thursday June 26, 2025 12:30pm - 12:40pm MDT
Bluebird Ballroom 3B

2:15pm MDT

Shadow Vulnerabilities in AI/ML Data Stacks - What You Don’t Know CAN Hurt You - Mic McCully, Oligo Security
Thursday June 26, 2025 2:15pm - 2:35pm MDT
Open-source AI software introduces a new family of vulnerabilities to organizations. Some components in AI, like model serving, include Remote Code Execution (RCE) by design, like when loading pre-trained models from external sources.

This talk will examine some of the common security anti-patterns prevalent in AI engineering, such as security issues that are not classified as CVEs by design, or patched security issues that introduce breaking changes and therefore are not practically implemented. We’ll review the methods introduced for better security hygiene such as new checkpoint formats (model files on disk) - like SavedModel and SafeTensors.

While SCA, SAST, and traditional approaches don't analyze model checkpoints, leaving these silent vulnerabilities in your stacks, we’ll demo through real code examples, why the runtime context is crucial to detect these security issues––and how this can be achieved by leveraging eBPF and open source tooling.
Speakers
avatar for Mic McCully

Mic McCully

Field CTO, Oligo Security
Mic is an experienced senior security advocate who has spent his career evangelizing security software as a business enablement solution in some of the earliest security startups, as well as in significant positions within leading global security software enterprises. His security... Read More →
Thursday June 26, 2025 2:15pm - 2:35pm MDT
Bluebird Ballroom 3B

2:40pm MDT

Evangelizing Security in India: Fears, Tears, and a Billion Deaf Ears - Ram Iyengar, Linux Foundation
Thursday June 26, 2025 2:40pm - 2:50pm MDT
This is a short session about my experiences in the past 18 months carrying the story of open source security across the length and breadth of India.
It is a geography that is just maturing in the IT spectrum, shifting from a predominantly services mindset to one of building products for the world.
This is a story of opportunities, of troubles, of tiresome evenings, and me questioning my life choices in airports as I battle flight delays and doom scrolling.
What does the country with the world’s largest developer population offer? A way forward? A threat of immaturity overpowering technical potential? A path to shape the developer mindset from the outset?
I don’t have all the answers. Maybe you do.
Speakers
avatar for Ram Iyengar

Ram Iyengar

Open Source Evangelist, Linux Foundation
Ram Iyengar is an engineer by practice and an educator at heart. He was (cf) pushed into technology evangelism along his journey as a developer and hasn’t looked back since! He enjoys helping engineering teams around the world discover new and creative ways to work. He is a proponent... Read More →
Thursday June 26, 2025 2:40pm - 2:50pm MDT
Bluebird Ballroom 3B

2:55pm MDT

Simplifying SBOM Management: An Introduction To Bomctl - Allen Shearin & Ian Dunbar-Hall, Lockheed Martin
Thursday June 26, 2025 2:55pm - 3:05pm MDT
Bomctl is a new OpenSSF sandbox project designed to bridge the gap between SBOM generation and analysis. Leveraging the flexible and powerful expression of the Protobom library, bomctl
is natively format-agnostic, allowing effortless interaction with various SBOM formats. Bomctl enables the creation of to build a reference graph of SBOM documents and software packages, accurately representing modern software systems. With bomctl, data can be seamlessly pulled from SBOM generation tools and Source Code Management (SCM) platforms, and then pushed to SBOM registries, SCM platforms, and vulnerability analysis tools, streamlining your SBOM management workflow.
Speakers
avatar for Allen Shearin

Allen Shearin

Senior Full Stack Engineer, Lockheed Martin
Lockheed Martin Software Factory, Secure Software Supply Chain Team, Open Source Ecosystem Team. Active with a few OpenSSF projects, maintainer of bomctl.
avatar for Ian Dunbar-Hall

Ian Dunbar-Hall

Open Source Program Office, Lockheed Martin
Ian is a holds the position of Chief Engineer for Lockheed Martin Software Factory and specializes in DevSecOps and full stack engineering. Additionally he is a maintainer on SBOMit and an OpenSSF Governing Board General Member Representative.
Thursday June 26, 2025 2:55pm - 3:05pm MDT
Bluebird Ballroom 3B

3:10pm MDT

Enhancing Supply Chain Security: Integrating Zarf and GUAC for Seamless SBOM Generation and Delivery - Brandt Keller, Defense Unicorns
Thursday June 26, 2025 3:10pm - 3:30pm MDT
Software supply chain security is a critical concern for organizations operating in both connected and disconnected environments. The OpenSSF projects Zarf and GUAC (Graph for Understanding Artifact Composition) provide complementary capabilities to enhance security and transparency. Zarf enables the secure packaging and deployment of software in connected or disconnected environments, while GUAC aggregates and contextualizes Software Bill of Materials (SBOMs) to improve software provenance and risk assessment.

This talk will explore how integrating Zarf and GUAC can streamline SBOM generation, verification, and delivery across connected and disconnected environments. We will demonstrate how this integration facilitates:
- Secure SBOM packaging and transport with Zarf.
- Automated SBOM generation and enrichment using GUAC.
- Improved traceability and risk assessment in airgapped environments.

Attendees will gain practical insights into leveraging these OpenSSF projects to strengthen their supply chain security posture and meet emerging compliance requirements.
Speakers
avatar for Brandt Keller

Brandt Keller

OSS Maintainer, Defense Unicorns
Brandt is a Software Engineer with a passion for Open Source. As a Maintainer and Contributor to multiple Open Source projects, he finds distinct pleasure in solving difficult problems and being a voice for Critical - Regulated - and Air-Gapped environments (most often all of the... Read More →
Thursday June 26, 2025 3:10pm - 3:30pm MDT
Bluebird Ballroom 3B

3:35pm MDT

PQC & Crypto Agility: Hybrid Certificates, Different Formats, and Migration Strategies - Sven Rajala, Keyfactor
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Sven will cover hybrid cryptography in the context of post-quantum cryptography (PQC), examining the reasoning behind hybrid systems and their role in ensuring interoperability during migration while strengthening security against quantum threats.

He will also discuss hybrid PKI, exploring various proposed standards, their advantages and drawbacks, and their practical applications. Additionally, he will outline different PKI migration paths, providing strategies tailored to diverse organizational needs.

As organizations and solutions navigate the quantum horizon, it is essential to consider their unique circumstances when planning for the transition.
Speakers
avatar for Sven Rajala

Sven Rajala

Senior Solution Engineer, Keyfactor
Sven Rajala is a cybersecurity geek with 17+ years of expertise in PKI, automating PKI/signing solutions, and mastering containers. Known for sharing insights on PKI, EJBCA, and DevSecOps through YouTube tutorials, KEYMASTER sessions (@KeyfactorCommunity), and forums, he often infuses... Read More →
Thursday June 26, 2025 3:35pm - 3:50pm MDT
Bluebird Ballroom 3B

4:10pm MDT

OpenSSF TTX Panel Session - Speakers To Be Announced
Thursday June 26, 2025 4:10pm - 5:40pm MDT
Thursday June 26, 2025 4:10pm - 5:40pm MDT
Bluebird Ballroom 3B

5:40pm MDT

Closing Remarks - Speaker To Be Announced
Thursday June 26, 2025 5:40pm - 5:45pm MDT
Thursday June 26, 2025 5:40pm - 5:45pm MDT
Bluebird Ballroom 3B
 
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.