9:00am • Welcome + Opening Remarks - Steve Fernandez, General Manager, OpenSSF, The Linux Foundation
9:15am • Keynote: Security Work isn't Special - Seth Larson, Security Developer-in-Residence, Python Software Foundation
9:30am • Keynote: Sarah Evans, Distinguished Engineer, Dell Technologies
9:45am • Keynote Session To Be Announced - Andrew Carney, Program Manager, Information Innovation Office, DARPA
10:10am • Taming the Wild West of ML: Practical Model Signing With Sigstore on Kaggle - Mihai Maruseac, Google
10:30am • Who Are You Building For: Pipelines Have a Purpose - Andrew McNamara & Julen Landa Alustiza, Red Hat
10:55am • Myths Developers Believe About Open Source Security - Jess Lowe & Tim Zhang, Google
11:25am • Living Off the Pipeline: From Supply Chain 0-Days To Predicting the Next XZ-like Attacks - François Proulx, BoostSecurity.io
11:25am • Trends and Insights from the Sigstore Ecosystem - Eve Martin-Jones & Hayden Blauzvern, Google
11:50am • From Model To Trust: Building Upon Tamper-proof ML Metadata Records - Mihai Maruseac, Google & Eoin Wickens, HiddenLayer
12:10pm • Predicting OSS Vulnerabilities Through Communication Analysis: A Work in Progress - Shlok Gilda, University of Florida
12:30pm • Beyond the Bot: Building Secure and Resilient AI Agents With Open Source - Mihai Maruseac, Google & Sarah Evans, Dell Technologies
2:15pm • SLSA Dependency Track Update - Meder Kydyraliev, Google & Adrian Diglio, Microsoft
2:40pm • The Open Source SDLC Control Plane: Building the Supply Chain Security Sandwich - Michael Lieberman, Kusari & Eman Abu Ishgair, Purdue
2:55pm • Navigating Security in Generative AI Development - Katherine Druckman, Intel Corporation
3:10pm • Harnessing In-toto Attestations for Security and Compliance With Next-gen Policies - Marcela Melara, Intel Labs & Trishank Kuppusamy, Datadog
3:35pm • Signing and Verifying Multi-architecture Containers With Sigstore - Natalie Somersall, Chainguard
10:10am • Bridging the Chasm: Filling the Security Knowledge Gap Between Academia and Industry - Michael Biocchi, Snyk
10:30am • OSPS: All Your Base Are Belong To Us - Christopher Robinson, OpenSSF & Eddie Knight, Sonatype
10:55am • A Dashboard for Actionable OpenSSF Scorecard Insights - Tracy Ragan, DeployHub, Inc.
11:50am • Democratizing Cloud Native Security: How CNAMM Drives Evidence-Based Maturity - Abdel Sy Fane, DevSecFlow
12:10pm • Securing Public Sector Supply Chains Is a Team Sport - Daniel Moch, Lockheed Martin
12:30pm • SWAG: Bringing Software Security Best Practices To the Web - Daniel Appelquist, Samsung
2:15pm • Shadow Vulnerabilities in AI/ML Data Stacks - What You Don’t Know CAN Hurt You - Mic McCully, Oligo Security
2:40pm • Evangelizing Security in India: Fears, Tears, and a Billion Deaf Ears - Ram Iyengar, Linux Foundation
2:55pm • Simplifying SBOM Management: An Introduction To Bomctl - Allen Shearin & Ian Dunbar-Hall, Lockheed Martin
3:10pm • Enhancing Supply Chain Security: Integrating Zarf and GUAC for Seamless SBOM Generation and Delivery - Brandt Keller, Defense Unicorns
3:35pm • PQC & Crypto Agility: Hybrid Certificates, Different Formats, and Migration Strategies - Sven Rajala, Keyfactor
4:10pm • OpenSSF TTX Panel Session - Speakers To Be Announced
5:40pm • Closing Remarks - Speaker To Be Announced