This mini summit will bring together maintainers, security practitioners, identity experts, and open source community leaders to explore a practical question: how can open source projects know that critical contributors and maintainers are real, trusted participants without creating centralized identity databases or compromising privacy?
The session will focus on the ToIP Decentralized Trust Graph Working Group and its emerging work around verifiable trust communities, verifiable relationship credentials, proof of personhood, and maintainer verification for open source projects. The work is directly relevant to the Linux kernel, where the existing PGP web-of-trust model has provided an important foundation but is difficult to scale across the broader open source ecosystem. The LFDT progress report specifically connects this initiative to the Linux kernel project and the need for privacy-preserving maintainer trust infrastructure following supply-chain threats such as the XZ attack.
How to Register: Pre-registration is required. To register for Decentralized Trust for Open Source Maintainers Mini Summit, add it to your
Open Source Summit Europe registration.