Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Club E (Floor 1) clear filter
arrow_back View All Dates
Thursday, October 8
 

10:50 CEST

Verifying ABI Compatibility Across Releases and CPU Architectures - Adarsh Jagadish Kamini & Daniel Turull, Ericsson Software Technology
Thursday October 8, 2026 10:50 - 11:30 CEST
Package updates across multiple architectures and long-term release branches complicate pipeline testing. Source-level tests usually pass during a package upgrade, missing Application Binary Interface (ABI) changes that later break downstream images and containers at runtime.

This talk introduces an extension to meta-binary-audit [1] that adds automated binary analysis to release CI pipelines for Yocto environments. Integrating libabigail into the pipeline reports exactly what changed in the binary interface before code is released.

The session details the CI architecture, parallel binary audits across multiple architectures, and how to track symbol-level ABI changes during LTS uplifts, using the migration from Scarthgap to Wrynose as an example. Attendees will leave with practical methods to analyze these interface changes, evaluate compatibility across releases, and prevent broken downstream images.

[1] https://github.com/Nordix/meta-binaryaudit/
Speakers
avatar for Daniel Turull

Daniel Turull

Senior Specialist in Operating Systems, Ericsson
Daniel is a senior specialist at Ericsson. Currently, he focuses on embedded Linux with Yocto, working on both internal and commercial distributions. He works on the Ericsson Linux distribution team, productifying Yocto and ensuring supply chain security to safeguard critical inf... Read More →
avatar for Adarsh Jagadish Kamini

Adarsh Jagadish Kamini

Linux Support Engineer, Ericsson Software Technology AB
Adarsh currently works as a Linux Support Engineer at Ericsson Software Technology in Stockholm. He has a broad background in engineering spanning embedded systems, connectivity, and robotics. However, he is most passionate about build systems, integrating devices and real-time systems... Read More →
Thursday October 8, 2026 10:50 - 11:30 CEST
Club E (Floor 1)

11:40 CEST

Same Tag, Different Risk: Catching Semantic SBOM Drift Across Multi-Arch Containers - Yogesh Sardana, Airtel
Thursday October 8, 2026 11:40 - 12:20 CEST
This isn't just about Airtel but for every organisation as multi-arch OCI manifest list lets one image tag resolve to different binaries per architecture, teams treat that tag as a single security unit, yet the amd64, arm64 & riscv64 builds underneath frequently diverge, a base-image bump, a differently resolved dependency version or missing backport can leave one architecture patched against CVE while another silently isn't & no scanner today compares SBOMs across the architectures inside same manifest list, each platform image is scanned in isolation & reported as N separate, ostensibly fine results. Talk introduces manifest-list-aware SBOM differ that pulls every per-architecture image inside tag, generates SBOM for each & diffs them against each other rather than against historical baseline, flagging any package, version or vulnerability status that differs across architectures sharing same tag, the same Dockerfile & same assumed security posture across every platform it claims to support. We show this catching real drift in popular base images, demo CI gate that blocks a push when architectures diverge unexpectedly & discuss how it slots into existing signing pipelines.
Speakers
avatar for Yogesh Sardana

Yogesh Sardana

Deputy General Manager - AI & Cloud Engineering, Airtel
I'm working as a Cloud Engineering Leader & Researcher, leading Open Source Stack R&D wing, known as Jack of all trades, master of Cloud. Been into various tech stacks of Software Development Life Cycle, having fun with tech.
Thursday October 8, 2026 11:40 - 12:20 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

13:50 CEST

Still Leading the Pack: Modernizing Kubernetes Supply Chain Security - Adolfo García Veytia, Carabiner Systems & Carlos Tadeu Panato Junior, Chainguard
Thursday October 8, 2026 13:50 - 14:30 CEST
Container image signing, SBOMs, SLSA attestations.... five years ago, the Kubernetes project was a trailblazer securing its releases using these and other security features. Having developed its own tools and solutions, things "just worked" for the project, but security technologies evolve and so have we.

Join us as as we dig deep to explore and compare the metadata the project started producing in 2021 with how modern supply chain tools expect them today.

During this talk, we'll do an overview of the updates and modernization of the Kubernetes secure build process and tools. We will examine visually the quality improvements to the Kubernetes SBOMs, how we migrated the SLSA provenance we use to gate our releases to SLSA v1, signing into Sigstore bundles, and, most importantly, how the the toolchain built by K8s Release Engineering enables more than a hundred independently managed projects under the Kubernetes umbrella to build and ship security features to protect themselves and their users.

Out tooling is available for anyone so perhaps we can inspire you to to the same for your projects!
Speakers
avatar for Carlos Panato

Carlos Panato

Staff Software Engineer, Chainguard
Carlos Panato (@cpanato) is a Staff Software Engineer at Chainguard, Inc., specializing in development and infrastructure with Kubernetes and containers. He has a diverse background in development, testing, processes, and management. Carlos actively contributes to several Linux Foundation... Read More →
avatar for Adolfo Garcia Veytia

Adolfo Garcia Veytia

Founding Engineer, Carabiner Systems
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
Club E (Floor 1)
  Packages & Images & Containers

14:40 CEST

No Slides, No Pitches: What Practitioners Really Think of OpenSSF Tools - Katherine Druckman, JetBrains; Kadi McKean, ReversingLabs; Tabatha DiDomenico, G-Research Open Source
Thursday October 8, 2026 14:40 - 15:20 CEST
Somewhere along the way, the security ecosystem started asking maintainers to add more steps, update more plugins, and generate more outputs, without asking what it costs them. At cdCon, the OpenSSF DevRel community ran two back-to-back sessions to fix that: first an open, no-pitches roundtable where practitioners told us where tools miss the mark, then a maintainer lightning round where the people who could act on that feedback were already in the room.

This talk distills what came out of both. We'll cover the adoption gap (lots of awareness, far less implementation), why a year on this community still doesn't trust the SBOMs it generates, the recurring "I have one security engineer — where do I start?" problem, and the confusion created by too many badges and not enough wayfinding. Then we'll show how a wave of OpenSSF projects — from gittuf and Sigstore to OpenVEX, SBOMit, and the OSPS Baseline — are responding, including where there is work to do.
Speakers
avatar for Tabatha DiDomenico

Tabatha DiDomenico

OSS Security Engineer, G-Research Open Source
Tabatha DiDomenico is part of the Open Source team at G-Research focusing on supply chain security, secure open source practices, and community and developer relations.

Tabatha is president of Security BSides Orlando, co-host of the GR-OSS Out podcast and holds an MS in Cybersecurity from the University of South Florida. She has spoken at conferences including Black Hat Tools Arsenal, SOSS Fusion, ShmooCon, and Grace Hopper Celebration... Read More →
avatar for Kadi McKean

Kadi McKean

Community Manager, ReversingLabs
Kadi is passionate about the DevOps / DevSecOps community since her days of working with COBOL development and Mainframe solutions. At ReversingLabs, she collaborates with developers and security researchers to educate the open source community on software supply chain security. She... Read More →
avatar for Katherine Druckman

Katherine Druckman

Head of Community and Partnership Engagement, JetBrains
Katherine Druckman is a senior technologist, speaker, and longtime advocate for open ecosystems. Currently Head of Community and Partnership Engagement at JetBrains, she specializes in developer experience, combining software ecosystem strategy, content strategy, and community building... Read More →
Thursday October 8, 2026 14:40 - 15:20 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

15:50 CEST

Maven-Lockfile: Locking Down the JVM Supply Chain for Hermetic Builds - Aman Sharma, KTH Royal Institute of Technology & Bruno Pimentel, Red Hat
Thursday October 8, 2026 15:50 - 16:30 CEST
Modern software projects depend on hundreds of third-party libraries, making reproducible and secure builds increasingly difficult. However, Maven, one of the most widely used Java build tools, has no native lockfile support. This leaves projects exposed to version drift, tampered artifacts, and dependency confusion attacks, while making hermetic builds difficult to achieve.

Maven-lockfile addresses this by generating a cryptographic record of all resolved artifacts, including transitive dependencies, and validating them on every build. This enables frozen dependency sets for exact historical reproducibility. In collaboration with Red Hat, we extended maven-lockfile to systematically capture build extensions, BOMs, and other dynamically fetched artifacts required for hermetic builds, and compare it against Maven-native approaches like Trusted Checksums.

To complete the workflow, we demo maven-lockfile alongside Hermeto, a CLI tool that pre-fetches dependencies into a local cache, enabling fully network-isolated builds.
Speakers
avatar for Aman Sharma

Aman Sharma

PhD Student, KTH Royal Institute of Technology
I am a PhD student at KTH Royal Institute of Technology, Stockholm, Sweden and a researcher in CHAINS project funded by the Swedish Foundation for Strategic Research. We work on securing software supply chains. Before that, I received my Bachelor in Technology from Indian Institute... Read More →
avatar for Bruno Pimentel

Bruno Pimentel

Software Engineer, Red Hat
Software Engineer @ Red Hat
Thursday October 8, 2026 15:50 - 16:30 CEST
Club E (Floor 1)

16:40 CEST

From Source To Wheel: Solving Python's Bootstrapping Problem - Rohan Devasthale & Christian Heimes, Red Hat
Thursday October 8, 2026 16:40 - 17:20 CEST
When you run pip install numpy, pip downloads a pre-built binary someone else compiled. For most developers that's fine, but in regulated environments or anywhere supply chain integrity matters, it's a gap one that incidents like the LiteLLM PyPI compromise and fake DeepSeek packages have made harder to ignore.

There's a bootstrapping problem too: building numpy needs setuptools, and building setuptools needs… setuptools. Every existing tool pip, uv, conda breaks this cycle by quietly downloading pre-built binaries. None give you a unified view of the full dependency tree, making it hard to audit what was built, from where, and in what order.

This talk walks through an unsolved problem in Python packaging bootstrapping entire dependency trees from source and how Fromager tackles it using PEP 517. We'll cover:

1. Why pip install --no-binary :all: doesn't get you to "built from source"
2. Where pip, Nix, Spack, and Bazel each fall short
3. The two-stage discover/build split and the JSON artifacts it produces for auditing
4. Why building packages as collections keeps them ABI-compatible critical for stacks like PyTorch with CUDA/ROCm native code
Speakers
avatar for Rohan Devasthale

Rohan Devasthale

Senior Software Engineer, Red Hat
Hi! I am a Senior Software Engineer at Red Hat and an open source enthusiast based in the United States. I enjoy coding and use of AI to automate things. Apart from technical work, I like to travel and explore new places. I am a foodie and also play badminton.
avatar for Christian Heimes

Christian Heimes

Senior Principal Software Engineer, Red Hat

Thursday October 8, 2026 16:40 - 17:20 CEST
Club E (Floor 1)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -