Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Conference Hall (Floor 4) clear filter
Wednesday, October 7
 

11:20 CEST

How Uber Uses Intelligent Agents for Open Source Governance - Chris Howard, Uber
Wednesday October 7, 2026 11:20 - 11:40 CEST
Open Source compliance is no longer just about coping with legal headaches; between navigating the Cyber Resilience Act & managing strict SBOM mandates it is a critical regulatory hurdle. Enforcing these standards without slowing developer velocity is a giant challenge. To solve this, the Uber OSPO overhauled our ecosystem of 6 Monorepos, 4k microrepos & over 35k dependencies to move away from manual audits & remove the friction placed on our engineers.
We built a system that scans our entire codebase every 24 hours, but detection is only half the battle. By integrating agentic tooling with our compliance policies & historical exception data, our system now makes calculated judgments on resolution versus escalation. The OSPO agent autonomously raises tickets, remediates issues & learns how to handle complex scenarios that would have required legal insight. This has automated our checks and eradicated high risk libraries from our codebase.
It’s not all as complex as it looks though. With clear policies, legal alignment, and a commitment to learning by doing, any organisation can do this. I'll share Uber's blueprint for turning open source governance into an automated & smart engine.
Speakers
avatar for Chris Howard

Chris Howard

Head of Open Source, Uber
Chris is a specialist Open Source strategist and community builder dedicated to fostering healthy developer ecosystems.
As Head of the OSPO at Uber, he leads global strategy for open-source consumption, contribution, and Developer Relations. He previously spearheaded the OSPO at EPAM, where he focused on maturing open-source programs and scaling contributions for global clients... Read More →
Wednesday October 7, 2026 11:20 - 11:40 CEST
Conference Hall (Floor 4)

11:40 CEST

How Open Source Communities and OSPOs Are Responding To AI Assisted Contributions - Norio Kobota & Alin Jerpelea, Sony
Wednesday October 7, 2026 11:40 - 12:00 CEST
Open source communities are entering a new phase as more contributions are created with AI assistance. This raises a practical question for the ecosystem: how should projects, maintainers, and companies handle AI-assisted contributions while preserving accountability, trust, and review quality?

This session brings together two complementary perspectives:
1. An outside-in view of how open source communities are responding, including early observations on how such contributions are being identified and categorized, and
2. An inside-out view of what this shift means for OSPO strategy, compliance, and coordination across engineering, legal, IP, and security stakeholders.

Rather than debating AI in the abstract, the talk focuses on concrete issues communities and companies are already facing, including human accountability, maintainer workload, traceability, stewardship, and software supply chain quality.

Attendees will leave with a practical framework for discussing AI-assisted contributions inside their projects, OSPOs, and cross-functional governance teams.
Speakers
avatar for Norio Kobota

Norio Kobota

Senior Open Source Strategist, Sony Group Corporation
Norio Kobota is a Senior Open Source Strategist in Sony Group Corporation. He is the chair of Open Source Software License Committee in Sony and works to improve OSS compliance and relationships with OSS communities.
He represents Sony as a board member of OpenChain Project. And he is participating the SPDX Project and contributing the SPDX Lite profile... Read More →
avatar for Alin Jerpelea

Alin Jerpelea

Senior Architect, Sony
Alin Jerpelea is a senior software architect and a local OSPO member at Sony, located in Lund, Sweden.
He has been part of Sony since 2010 when he joined Sony Mobile as a community manager for the Xperia Open Source initiative and has since worked in numerous projects and Open So... Read More →
Wednesday October 7, 2026 11:40 - 12:00 CEST
Conference Hall (Floor 4)

13:30 CEST

Panel Discussion: The Latest From TODO Group: Advocacy, Community, and Our AI Initiatives - Natali Vlatko, Cisco; Georg Kunz, Ericsson; Ana Jiménez Santamaría, Linux Foundation; Annania Melaku, F5 NGINX
Wednesday October 7, 2026 13:30 - 14:10 CEST
The TODO Group’s mission is to empower and educate open source management best practices inside organizations through effective Open Source Program Offices (OSPOs) and similar initiatives. With the latest developments in AI, as well as the shift of importance in open source across different industries, several new initiatives have been spun up that the community has embraced with fresh energy.

Join the TODO Group Steering Committee as they present the latest updates from the community, including a new Working Group focused on agentic AI tooling for OSPOs, changes to how our content is created and shared, as well as the growth in local events by TODO Group Ambassadors from around the world. The Steering Committee will also share the data they’re collecting in partnership with LF Research that informs ecosystem trends worth exploring and what the TODO Group community wants to focus on most in terms of learnings and growth.

Plan on attending if you’re in an OSPO, looking to create one at your organization, or interested in helping to spin up new open source initiatives!
Speakers
avatar for Annania Melaku

Annania Melaku

Lead, Open Ecosystem Programs, F5
Annania Melaku leads Open Ecosystem Programs at F5, spanning open source, open standards, open source AI, and cross-ecosystem collaboration. She also serves on the steering committee of the TODO Group, the Linux Foundation community for Open Source Program Offices. With a background... Read More →
avatar for Georg Kunz

Georg Kunz

Director Open Source Software, Ericsson
Georg is a director in Ericsson's Open Source Program Office. He is a passionate advocate for open source software and a long term contributor to a wide range of open source projects. He currently serves on the Technical Advisory Council and the Governing Board of the Open Source... Read More →
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
avatar for Natali Vlatko

Natali Vlatko

Director of Open Source Software Engineering, Cisco
Natali Vlatko (she/her) is a Director of Open Source Software Engineering at Cisco, specializing in open software, policy, and governance. She is a SIG Docs Co-Chair for Kubernetes and a member of the TODO Group Steering Committee. She plays on the fun computer in her spare time... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Conference Hall (Floor 4)

14:25 CEST

Open Source as a Government Goal: Berlin’s Strategy for Digital Sovereignty – Lessons Learned - Marcel Scholze, PwC Germany & Florian Ebel, Senatskanzlei Berlin
Wednesday October 7, 2026 14:25 - 14:45 CEST
Everyone is talking about digital sovereignty - but what happens when a federal state takes this concept seriously? In 2025, Berlin adopted an Open Source strategy to achieve innovation and digital independence through OSS, open standards, and collaboration.
We report on how this strategy came about and what its implementation means in a complex administrative landscape. Seven measures form the backbone—from establishing an OSPO at ITDZ Berlin to identifying critical software dependencies to giving Open Source priority in procurement law. Behind each measure lie organizational, cultural, and legal challenges.
What are the low-hanging fruits? Where do strategies reach their limits? And how do you keep a “learning” strategy alive - rather than letting it fizzle out? An honest account of progress and setbacks that shows what others - whether government agencies or companies - can learn from Berlin’s Open Source journey.
Speakers
avatar for Florian Ebel

Florian Ebel

Head of Strategy and Governance Unit (CDO-Department), Senatskanzlei Berlin

avatar for Marcel Scholze

Marcel Scholze

Director, PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft
Marcel Scholze is a Director at PwC Germany leading the firm's Open Source and Digital Sovereignty practice. He has shaped OSS strategies and enablement programs for organizations across the public sector and industry. With a background in large-scale IT sourcing, he brings a pragmatic... Read More →
Wednesday October 7, 2026 14:25 - 14:45 CEST
Conference Hall (Floor 4)

14:45 CEST

Strategic Approach To Demonstrating the Value of OSS Efforts - Dawn Foster, Fast Wonder
Wednesday October 7, 2026 14:45 - 15:05 CEST
We’ve probably all had leadership question the value of our OSS efforts. It can be difficult to frame the value in ways that resonate with stakeholders and clearly articulate the benefits gained through continued OSS contributions. Taking a strategic approach that connects the OSS work with the broader goals and objectives of the organization can demonstrate the value of this work so that the organization can continue to allocate resources to the OSPO or other OSS teams.

Using examples from my decades of experience in OSS, this talk will provide details about how to demonstrate value by focusing on how your OSS work helps the organization achieve their strategies and goals. Every organization has unique needs and goals based on what they are trying to achieve, so there is no “one size fits all” way of demonstrating value, but aligning your OSS strategy with your organization’s goals and focusing on the most strategic projects can help show the value of your efforts. This talk will help you reason about how OSS efforts allow your organization to achieve its goals along with framing and communicating that value in ways that resonate with leadership, funders, and stakeholders.
Speakers
avatar for Dawn Foster

Dawn Foster

Open Source Strategy Consultant, Fast Wonder
Dr. Dawn Foster is an OSS strategy consultant. She is also on the board of CHAOSS, OpenUK, and the Software Stewardship Lab. She was previously a co-chair of the CNCF Contributor Strategy TAG. She has 20+ years of experience at companies like VMware and Intel with expertise in strategy... Read More →
Wednesday October 7, 2026 14:45 - 15:05 CEST
Conference Hall (Floor 4)

15:35 CEST

BoF: Open by Default or Intent: Inflection Points for Public Sector Open Source Decisions - Clare Dillon, CURIOSS; Remy DeCausemaker, CMS.gov; Johan Linåker, RISE Research Institutes of Sweden; Karel Rietveld, Netherlands Tax Administration
Wednesday October 7, 2026 15:35 - 16:15 CEST
Many organizations have bought into the value of open source, but don't choose to open source everything. This Bird of a Feather session focuses on the inflection points for public sector organizations: what actually causes an organization to move projects from closed source to Open Source, or — just as importantly — to make a deliberate call that something should stay closed. The triggers are rarely just technical. Public Sector organizations may consider the ROI on open sourcing; whether the codebase, the team, and the organization are actually in a position to do this well; if there are regulatory obligations or policy considerations that push you towards being more open or closed. Sometimes the honest answer is that the perceived collaboration overhead (e.g. documentation, governance) may not be worth it for code that's considered throwaway or not ready for public consumption. Session participants will include researchers, representatives from InnerSource Commons and OSPOs in public sector organizations who have experience navigating these decisions.
Speakers
avatar for Clare Dillon

Clare Dillon

Community Lead, CURIOSS
Clare Dillon is community lead for CURIOSS, a community for university and research institution OSPOs. Clare is also a PhD researcher with Lero, the Science Foundation Ireland Research Centre for Software and a member of Lero's OSPO team. Clare was the inaugural Executive Director... Read More →
avatar for Remy DeCausemaker

Remy DeCausemaker

Acting Director, OSPO, CMS.gov
Remy DeCausemaker is the Acting Director of the Open Source Program Office at the Centers for Medicare & Medicaid Services (CMS.) Remy helps developers, designers, and other contributors work with dedicated civil servants to create open accessible health technology projects, programs... Read More →
avatar for Johan Linaker

Johan Linaker

Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, RISE Research Institutes of Sweden
Johan Linåker is a Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, working at the intersection of empirical software engineering, open technologies, and digital sovereignty. His work focuses on how public and private... Read More →
avatar for Karel Rietveld

Karel Rietveld

Open Source Program Office lead, Netherlands Tax Administration
Working within the Chief Technology Office in building an Open Source Program Office for the Netherlands Tax administration, Customs and Benefits
Wednesday October 7, 2026 15:35 - 16:15 CEST
Conference Hall (Floor 4)

16:30 CEST

MCP and AI Protocols: Questions for Open Source Managers - Ana Jiménez Santamaría, Linux Foundation
Wednesday October 7, 2026 16:30 - 16:50 CEST
Open protocols are creating a new layer of infrastructure for how AI agents connect to tools, data, and each other. For OSPOs and open source managers, this also creates a new governance surface: How should open source repositories document instructions for AI agents?; What policies are needed for AI-assisted contributions?; How can OSPOs help bring an open source perspective into agentic AI policies and processes while working with the teams responsible for security, legal and platform engineering?

This talk will introduce the basic concepts behind the open agent protocol landscape, with a special focus on the Model Context Protocol (MCP), and explore how OSPOs can apply this knowledge to open source policies, developer experience, contribution workflows, and reporting

The session will close with a few open questions and practical considerations for open source managers starting to explore this space, including how collaborative efforts such as TODO Group’s Agentic AI to Empower OSPOs initiative can help the community build in collaboration
Speakers
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
Conference Hall (Floor 4)

16:50 CEST

AI Everywhere, Trust Nowhere: Navigating Open Source Security, "AI Slop," and the New Attack Surface - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Wednesday October 7, 2026 16:50 - 17:10 CEST
Artificial Intelligence is fundamentally changing the open-source ecosystem, promising unparalleled development velocity. However, this speed scales risk simultaneously. Open-source software (OSS) maintainers—already heavily resource-constrained and unevenly funded—are finding themselves caught in a crossfire of AI-driven complications.

This session, led by the Open Source Security Foundation (OpenSSF), breaks down the three critical security paradigm shifts introduced by AI:

Securely Using AI to Build Software: How insecure-by-default code suggestions, copied risks, and hallucinated packages compromise codebase integrity.

Using AI to Secure Software: The reality of how upstream maintainers are overwhelmed by a massive influx of automated vulnerability reports generated by AI bug hunters.
AI as an Attack Surface: Moving past traditional DevSecOps to address MLSecOps pipeline vulnerabilities, including data poisoning, model theft, and container security across the machine learning lifecycle.

Attendees will walk away with an understanding of OpenSSF’s recommended approach designed to shift the focus from cheap "findings" to valuable, validated "fixes".
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, Openssf
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

OpenSSF Chief of Staff, Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across a multitude of industries, including defense, heavy machinery... Read More →
Wednesday October 7, 2026 16:50 - 17:10 CEST
Conference Hall (Floor 4)

17:25 CEST

Panel Discussion: Open Source in Software-Defined World - Sven Jeroschewski, Robert Bosch GmbH; Ana Jiménez Santamaría, Linux Foundation; Cornelius Schumacher, DB Systel GmbH; Agustin Benito Bethencourt, Independent
Wednesday October 7, 2026 17:25 - 18:05 CEST
Many initially hardware-driven industries, undergo a profound transformation and become more defined by software like it is the case in the automotive industry. Driven by increasing software complexity, this shift demands unprecedented levels of collaboration and joint integration. As many organizations whose core business was not selling software accelerate towards a more software-defined world, a critical question is how to consume, grow, run and consume the involved Open Source projects to deliver lasting value.

While many of the effects of open collaboration are not unique to a particular domain, the lessons learned from already more "software-defined" industries unlock invaluable insights that are collected in the TODO Group Business Guide.

Taking the learnings from that guide, this panel will delve into how Open Source activities effectively contribute to reaching business goals.

Join us to uncover enablers of sustainable Open Source development, learn from cross-industry successes, and equip your teams with the necessary competencies to thrive in the rapidly evolving software-defined world.
Speakers
avatar for Sven Erik Jeroschewski

Sven Erik Jeroschewski

OSPO Member, Robert Bosch GmbH
Sven Erik Jeroschewski is a Software Engineer with the OSPO of the Robert Bosch GmbH. He combines Open Source strategy with software engineering and actively works within the automotive open-source ecosystem by acting as a committer for Eclipse Kuksa. Sven studied Computer Engineering... Read More →
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
avatar for Cornelius Schumacher

Cornelius Schumacher

Open Source Steward, DB Systel GmbH
Cornelius helps teams at Deutsche Bahn, the German railway company, to use and contribute to open source software. He has a background from more than two decades in the open source community and industry. Originally a software developer he now focus on management of open source.
avatar for Agustin Benito Bethencourt

Agustin Benito Bethencourt

Consultant, self-employed
Independent consultant, focused on increasing organizational performance in two ways:
1.- Through Tagoross, the forum for professionals at the crossroad of open source as strategy and business
2.- By supporting their journey towards becoming good open source citizens, including AI... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Conference Hall (Floor 4)
 
Friday, October 9
 

11:05 CEST

This Talk Is Already Out of Date: Planning for the Long Term in a Short Term World - Rebecca Rumbul, Rust Foundation
Friday October 9, 2026 11:05 - 11:45 CEST
Successful Open Source projects have always had to balance the need to work towards long term sustainability and growth with meeting shorter term issues such as immediate funding and human resourcing needs. Projects would generally work to an annual rhythm to align with budgeting and funding decisions made by corporate supporters, and annual planning cycles were in many places well established. However, this rhythm has been hugely impacted by the new age of AI and the pivots in focus of the commercial tech industry. Long term planning feels impossible, and funding work sustainably feels increasingly out of reach when projects are reliant on companies engaged in an AI arms race. Once-robust human processes now move too slowly to be effective, and the key individuals that still need to be a part of this new world increasingly feel like they are a day late and a dollar short for everything. This talk looks at how the human side of Open Source is being affected by these shifts, and how communities can consider how to respond to these challenges.
Speakers
avatar for Dr. Rebecca Rumbul

Dr. Rebecca Rumbul

Executive Director & CEO, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Conference Hall (Floor 4)

11:55 CEST

Burnout in Open Source: A Structural Problem We Can Fix Together - Miranda Heath, Software Stewardship Lab
Friday October 9, 2026 11:55 - 12:35 CEST
I'm a psychologist and researcher at the [Software Stewardship Lab](https://stewardshiplab.org/). Moved by the extent of burnout among Open Source developers, I have written what I believe to be the most comprehensive report to date on burnout in Open Source. This entailed a review of the academic literature, a qualitative analysis of online discussion in the OSS community, and interviews with OSS maintainers.

I present 5 factors my research identified that contribute to developer burnout: difficulty getting paid, workload and time commitment, maintenance work as unrewarding, toxic community behaviour and hyper-responsibility. I discuss 3 structural changes we can make to address developer burnout: make it easier for OSS developers to get paid, distribute maintenance responsibilities, and strengthen developer community, solidarity and capacity for advocacy. Finally, I preview the findings of a follow-up study I am currently undertaking exploring the impact of the rise of AI coding on OSS developer burnout, including where it is exacerbating existing causes of burnout, and where it might help alleviate them.
Speakers
avatar for Miranda Heath

Miranda Heath

Director and Researcher, Software Stewardship Lab
Director and researcher at the Software Stewardship Lab, an applied research non-profit dedicated to ensuring the stability of the Open Source software ecosystem. I research burnout in Open Source, investigating the structural issues that put developers at risk of burnout and how... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Conference Hall (Floor 4)

14:00 CEST

Sustainable Communities - Risks and Remedies - Ildiko Vancsa, OpenInfra Foundation
Friday October 9, 2026 14:00 - 14:40 CEST
Whether you care about open source projects for the success of your business or to retain your basic human right to access digital technology, it is in your interest to understand the risks these communities face and what you can do to mitigate them.

This presentation will provide you with a list of risk factors, from bad practices to mindset, that imapct the sustainability of open source communities. The talk will provide details of studies and real-life experiences to outline why certain behaviors, practices and approaches, most often without any bad intentions, are harmful to the open source ecosystem.

You will also receive tools and actionable steps to improve the sustainability of the open source projects you care about. The session will also give you ideas how to implement practices into your workflow, whether you are relying on open source software as a buiness or as an individual.
Speakers
avatar for Ildiko Vancsa

Ildiko Vancsa

Director of Community, OpenInfra Foundation
Ildikó is working for the OpenInfra Foundation as Director of Community. She is the Community Manager for the StarlingX and the Kata Containers projects, and a co-leader of the OpenInfra Edge Computing Group. Ildikó is an evangelist of open collaboration and is using her experience... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Conference Hall (Floor 4)

14:50 CEST

X-Road: The Open Source Project That Runs Countries (And What It Can Teach Your Project) - Gbemisola Mary Oladetoun, Fleetfox
Friday October 9, 2026 14:50 - 15:30 CEST
X-Road started as Estonia's internal government data exchange layer. Today it is open source, deployed in over 20 countries including Finland, Iceland, and Japan, and maintained by a cross-border foundation. I build software on top of X-Road every day in Tallinn, so I interact with this system as a practitioner, not just someone who read about it.

This talk covers: the governance model that allows countries with different legal systems to contribute to the same codebase. How X-Road handles backwards compatibility when your users are governments that cannot afford breaking changes. The trust model that lets citizens see exactly who accessed their data. And what this journey from closed government software to open source infrastructure teaches other projects about sustainability.

I am not an X-Road maintainer. I am a software engineer who uses it in production and an HCI researcher who thinks about how people interact with systems like this. Most talks about X-Road come from the people who built it. This one comes from someone who lives with it.
Speakers
avatar for Gbemisola Mary Oladetoun

Gbemisola Mary Oladetoun

Full Stack Developer, Fleetfox
Gbemisola Oladetoun is a Full Stack Developer and HCI researcher at Tallinn University, Estonia. Originally from Nigeria, she has built AI-powered products serving 1,500+ users across three African countries and now builds fleet software for the European market. Her talks blend technical... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Conference Hall (Floor 4)

15:40 CEST

A Strategic Outlook for Digital Commons: Technology, Communities, and Governance - Nick Gates, OpenForum Europe
Friday October 9, 2026 15:40 - 16:20 CEST
Sovereignty rhetoric is creating new openings for commons-based approaches to organising around, governing, and investing in public digital infrastructure that works for a plurality of Member States. This is partly what is proposed via ongoing initiatives like the Digital Commons EDIC and the Open Internet Stack. That said, the European Commission risks absorbing them while adopting largely statist, protectionist, or purely industrial framings that hollow out their meaning.

This talk navigates that tension directly, drawing on research from the NGI Commons project to offer a clear-eyed account of where things stand and what communities, researchers, and advocates can do about it. This talk begins by mapping these concepts with precision: what each means, how they relate, and why the distinctions matter for anyone trying to advance a genuinely commons-based agenda as part of these existing initiatives.

From there, the talk examines the current EU policy moment: the sovereignty turn, the competitiveness and industrial policy logic now dominating digital debates, the AI race framing, and what these shifts mean for the digital commons and the EU’s broader tech sovereignty ambitions.
Speakers
avatar for Nick Gates

Nick Gates

Senior Policy Advisor, OpenForum Europe
Nick Gates is a Policy Advisor at OpenForum Europe, where he leads OFE’s work on the NGI Commons initiative and manages projects related to open source research and policy. Nick has significant experience in digital government, particularly around open source, public financial management... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Conference Hall (Floor 4)

16:30 CEST

Voluntary Transparency, Involuntary Security: A Maintainer's Guide To CRA Readiness - Roman Zhukov, Red Hat
Friday October 9, 2026 16:30 - 17:10 CEST
The enforcement window for the EU Cyber Resilience Act (CRA) is arriving, triggering corporate compliance panic. While individual open-source developers and volunteer maintainers have zero obligations under the CRA, their downstream commercial adopters face mandatory due diligence requirements. How do Maintainers survive being bombarded with manual security questionnaires and subtle attempts to shift regulatory liability upstream?

The co-chair of the OpenSSF Global Cyber Policy Working Group and co-creator of the CRA Readiness Guide for Maintainers will walk you through converting the OpenSSF voluntary checklist into automated repository-level defenses. Attendees will see how to deploy the open-source OSPS Baseline Scanner GitHub Action to perform security gap analysis, expose standardized project postures via machine-readable security-insights.yaml files, and anchor liability disclaimers into repositories to push due-diligence burdens back downstream.
Speakers
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product Security... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Conference Hall (Floor 4)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.