Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: South Hall 1 A (Floor 1) clear filter
Thursday, October 8
 

10:50 CEST

Panel: OpenChain 2.0: Open Source Compliance in the Age of Automotive SBOM, Generative AI, and the CRA - Masato Endo, Toyota Motor Corporation; Marcel Kurzmann, Robert Bosch GmbH; Meixia Wang, LF; Jimmy Ahlberg, Ericsson; Ayumi Watanabe, Hitachi
Thursday October 8, 2026 10:50 - 11:30 CEST
Ten years ago, the OpenChain Project launched at this very event. A decade on, it has built the global baseline for open source compliance, culminating in ISO/IEC 5230 — the "1.0" era. With Mary Meixia Wang as Executive Director, OpenChain now enters its next chapter, and this panel asks what "2.0" must deliver.

Two frontiers define the road ahead. First, Automotive SBOM: as vehicles become software-defined, the deepest supply chain anywhere needs SBOM practices scaling from silicon to OEM. Second, license compliance in the era of generative

AI and "vibe coding": as more code is generated by AI than written by hand, licensing of models, training data, and AI-produced code raises questions traditional compliance never anticipated. Regulation such as the EU CRA adds urgency, making machine-readable SBOMs effectively mandatory and reinforcing the trust and security OpenChain pursues.

The panel goes beyond discussion: it first shares the community's latest work on these challenges — from the Automotive SBOM Guideline to evolving thinking on compliance for AI-generated code — then opens a cross-industry conversation on what the shift from 1.0 to 2.0 must deliver in practice.
Speakers
avatar for Masato Endo

Masato Endo

Manager of TOYOTA OSPO, Toyota Motor Corporation
Masato Endo is a Group Manager of TOYOTA. He focuses also on building the Open Source governance structure within Toyota and developing relationships with the Open Source community, through projects such as AGL and OIN. From 2017, he began to work with the OpenChain Project as a board... Read More →
avatar for Marcel Kurzmann

Marcel Kurzmann

Software and Open Source Management Consultant, Robert Bosch GmbH
Marcel Kurzmann joined Bosch in 1997. After working at Bosch Engineering , Automotive Electronics and Bosch Software Innovations in different roles, he is now member of the Center of Excellence Open Source and Inner Source at Bosch Digital. He represents Bosch in the OpenChain Governing... Read More →
avatar for Meixia Wang

Meixia Wang

Executive Director, The Linux Foundation
Mary Wang is the Executive Director of the OpenChain Foundation, part of the Linux Foundation.

Prior to this role, she served as Director of the Open Source Ecosystem at Volvo Cars, where she founded and led the company’s Open Source Program Office (OSPO).
Mary also spent nine years at Ericsson. During that time, she worked as a DevOps engineer, developing and implementing CI/CD pipelines, and later as a Technical Product Manager (TPM), taking end-to-end ownership of products... Read More →
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
avatar for Ayumi Watanabe

Ayumi Watanabe

Senior OSS Specialist of Hitachi Solutions, Ltd., Hitachi Solutions, Ltd.
Ayumi Watanabe is a core member of OpenChain Japan community and known as an evangelist who is certified by the Linux Foundation Japan. Her strong point is a knowledge of many tools for SBOM generation and management, a wide range of experiences as an OSS management consultant, and... Read More →
Thursday October 8, 2026 10:50 - 11:30 CEST
South Hall 1 A (Floor 1)

11:40 CEST

Measuring What Matters: Building an Open Source Health Model for the Npm Ecosystem - Adam Herzog, AboutCode & Alyssa Wright, Bloomberg
Thursday October 8, 2026 11:40 - 12:00 CEST
Open source software powers critical digital infrastructure across every industry. But, how do you know if the software you are depending on is actually healthy? A project that looks active may have one key maintainer. A package you've never heard of may be a single point of failure for thousands of downstream projects. npm's scale and deep dependency chains turn that uncertainty into real supply chain risk – remember Shai-Hulud?

Based on learnings from open source community health analytics projects like CHAOSS, OpenSSF Scorecard, and GrimoireLabs, Bloomberg and AboutCode are building an open, data-driven framework that applies the Goal-Questions-Metrics methodology to assess project health across the npm ecosystem.

This talk presents our npm Health Model and open source tooling, early findings, and how this approach can extend to other OSS project ecosystems. We are sharing the model, methodology, data, and tooling openly so other organizations can apply it to their own processes. Attendees will leave with a practical framework for assessing open source health at scale, and a path to contributing to this open effort.
Speakers
avatar for Adam Herzog

Adam Herzog

Community, AboutCode
Adam leads the community for AboutCode, reusable open source building blocks of reliable data, interoperable tools, and practical standards to automate and secure software supply chains. He previously worked in different roles at (mostly) developer-facing startups, including field... Read More →
avatar for Alyssa Wright

Alyssa Wright

Open Source Program Office, Bloomberg
Alyssa Wright helps lead Bloomberg's Open Source Program Office, applying the principle of "be curious, solve problems, do good" to drive sustainable open source impact. Her experience spans the World Bank, Samsung Research, and board roles with Open Source Collective and OpenStreetMap... Read More →
Thursday October 8, 2026 11:40 - 12:00 CEST
South Hall 1 A (Floor 1)

12:00 CEST

How To Talk To Your Lawyer About Open Source - Jimmy Ahlberg & Georg Kunz, Ericsson
Thursday October 8, 2026 12:00 - 12:20 CEST
Have you ever felt frustrated that your legal counsel simply does not seem to understand what you are saying? Or are you a lawyer who simply cannot understand why the developers you are trying to help can’t speak clearly? Then you are not alone, and this is the session for you! Lawyers and engineers often speak different languages, which can lead to frustration when collaborating in an open source setting.

Removing friction between legal and engineering communication is no small task. However, doing so unlocks significant value: legal can provide clearer, more actionable advice and better understand risks, while engineers and developers gain a deeper understanding of that guidance. We will will share personal OSPO insights and practical strategies for enabling efficient, clear communication between these distinct functions.

The goal is not to turn engineers into lawyers or lawyers into software developers, but rather helps both sides understand and support each other more effectively. Without a shared language between engineering and legal, messages to management risk getting lost in translation. With clear communication we can all work more efficient together!
Speakers
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
avatar for Georg Kunz

Georg Kunz

Director Open Source Software, Ericsson
Georg is a director in Ericsson's Open Source Program Office. He is a passionate advocate for open source software and a long term contributor to a wide range of open source projects. He currently serves on the Technical Advisory Council and the Governing Board of the Open Source... Read More →
Thursday October 8, 2026 12:00 - 12:20 CEST
South Hall 1 A (Floor 1)

13:50 CEST

The Evolving OSPO: Driving Technology Governance and Strategic Value in the AI Era - Hiroshi Ota, LY Corporation & Meixia Wang, The Linux Foundation
Thursday October 8, 2026 13:50 - 14:30 CEST
As AI transforms the tech landscape through AI-generated code and new security threats, software supply chains and corporate environments face an unprecedented paradigm shift. Consequently, the OSPO's role is becoming more complex, requiring broad coordination across internal and external organizations. We will discuss how enterprises position their OSPOs to realize comprehensive strategic value—including governance and risk management—as well as the challenges they face.

In this joint presentation, Mary Meixia Wang (Executive Director of OpenChain) and Hiroshi Ota (Senior Manager of the Governance & OpenTech Division leading the OSPO at LY Corporation and a W3C Advisory Board member) will deliver a dialogue exploring the strategic convergence of open source, technical standards, and corporate technology governance.

To drive smooth operations and growth while mitigating technical risks, we will share the LY Corporation model. Through this case introduction, we will highlight the enterprise challenges such as the impact of AI and the expectations companies have for open-source communities like OpenChain. Responding to these realities, Mary will share OpenChain's global vision.
Speakers
avatar for Hiroshi Ota

Hiroshi Ota

Senior Manager, Governance & OpenTech Division / OSPO Lead, LY Corporation
Hiroshi Ota is the Senior Manager of the Governance & OpenTech Division at LY Corporation (LINE Yahoo), where he leads the corporate OSPO and comprehensive technology governance. He oversees a strategic organization that integrates open-source engagement, web standards, and technology... Read More →
avatar for Meixia Wang

Meixia Wang

Executive Director, The Linux Foundation
Mary Wang is the Executive Director of the OpenChain Foundation, part of the Linux Foundation.

Prior to this role, she served as Director of the Open Source Ecosystem at Volvo Cars, where she founded and led the company’s Open Source Program Office (OSPO).
Mary also spent nine years at Ericsson. During that time, she worked as a DevOps engineer, developing and implementing CI/CD pipelines, and later as a Technical Product Manager (TPM), taking end-to-end ownership of products... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
South Hall 1 A (Floor 1)

14:40 CEST

A Fork Load of Maintenance - Forking a Key Dependency - Tom Sadler & Joel Keers, BBC
Thursday October 8, 2026 14:40 - 15:00 CEST
The benefits of building software on top of open source solutions are well understood, such as avoiding reinventing the wheel, leveraging global expertise, and enabling interoperability. Another benefit is the ability to customise open source software for your use case, but in practice this will often be done by making a fork of the project, which can result in a significant maintenance overhead.

This talk is a case study of the BBC's fork of dash.js, a JavaScript library for media playback that is a key dependency for BBC web and connected TV apps. We will explore the reasons why a fork is being maintained, what the costs and benefits have been, and what is being done to reduce the maintenance overhead going forwards, including contributing to the mainline and engaging with the community. Attendees will come away with a better understanding of why and why not to fork, and how to reduce the burden of maintaining a fork.
Speakers
avatar for Tom Sadler

Tom Sadler

Senior Principal Software Engineer, BBC
Tom Sadler is a Senior Principal Software Engineer at the BBC, working with a number of teams on open source and industry engagement. He has led multiple teams working on the BBC’s Connected TV applications, with a focus on cross team collaboration. Tom has been a regular speaker... Read More →
avatar for Joel Keers

Joel Keers

Principal Software Engineer, BBC
Joel Keers is a Principal Software Engineer at the BBC with a focus on media playback for connected TV experiences. He's the lead maintainer on the BBC's open source TV playback library bigscreen-player and works with media playback experts within the BBC and the industry.
Thursday October 8, 2026 14:40 - 15:00 CEST
South Hall 1 A (Floor 1)

15:00 CEST

What You Need To Know About Project Health - Daniel Izquierdo Cortazar, Bitergia
Thursday October 8, 2026 15:00 - 15:20 CEST
Most organizations consuming open source have no systematic way to assess whether the projects they depend on are thriving, stagnating, or quietly dying. Scanners tell you about license, origin, and known vulnerabilities. Nothing tells you a maintainer is burning out or release cadence has silently stalled until it’s too late.

This talk introduces project health as a missing layer of supply chain risk management. We’ll cover the core metrics that matter from the work of CHAOSS (Community Health Analytics for Open Source Software) and how they complement security-focused efforts like OpenSSF Scorecard.

We’ll look at what’s ahead: making health data federated, queryable, and built into the tools and metadata infrastructure teams already use, so a health check becomes as automatic as a vulnerability scan. We’ll cover what’s being built now, what’s still unsolved, and how you can get involved.

Leave with a practical framework for evaluating dependency health today, and understand where this ecosystem is headed: toward a future where operationalized open health data at scale makes project health visible, measurable, and actionable for everyone who depends on open source.
Speakers
avatar for Daniel Izquierdo Cortazar

Daniel Izquierdo Cortazar

CEO, Bitergia
Daniel Izquierdo Cortazar, PhD in empirical software engineering, is the co-founder and CEO of Bitergia. A recognized expert in Open Source and InnerSource ecosystems, Daniel helps organizations make data-driven decisions regarding community health, corporate risk, and digital sovereignty... Read More →
Thursday October 8, 2026 15:00 - 15:20 CEST
South Hall 1 A (Floor 1)

15:50 CEST

Panel: Can University OSPOs Unlock Global Open Source Partnerships? - Stephanie Lieggi, UC Santa Cruz; Nithya Ruff, Independent; Clare Dillon, CURIOSS; Jacek Plucinski, University of Luxembourg
Thursday October 8, 2026 15:50 - 16:30 CEST
University researchers create innovative open source ecosystems that can reshape global digital infrastructure, however translating that work into sustainable partnerships with open source communities - and industry - remains difficult. Promising projects disappear based on funding cycles and student/faculty transience. Barriers to collaboration – IP issues, funding models, institutional culture – remain difficult to tackle. While these challenges are universal, the landscape looks different depending on in which part of the world you sit. Funding, technology transfer norms, and expectations from academic partners vary significantly between the EU and North American contexts. This panel brings together university OSPO practitioners to examine what a genuinely international model for university-industry open source collaboration could look like. They will share what's working in their ecosystems, where barriers lie, and whether shared infrastructure could bridge regional differences. The session includes space for audience input on what is most needed to make academic partnerships stronger at a global level.
Speakers
avatar for Stephanie Lieggi

Stephanie Lieggi

Executive Director, Center for Research in Open Source Software, UC Santa Cruz
Stephanie Lieggi is executive director for the Center for Research in Open Source Software (CROSS) and the UC Santa Cruz Open Source Program Office (OSPO). In her current roles she supports the work of academic-based open source projects and enables a sustainable contributor base... Read More →
avatar for Nithya Ruff

Nithya Ruff

Chair, Linux Foundation Board, Independent
Nithya has been in open source leader for over 25 years. She is a bridge builder working with companies large and small to create productive and strategic paths to working with open source. She led the Amazon OSPO & prior to Amazon, she started and grew Comcast and SanDisk's OSPO... Read More →
avatar for Clare Dillon

Clare Dillon

Community Lead, CURIOSS
Clare Dillon is community lead for CURIOSS, a community for university and research institution OSPOs. Clare is also a PhD researcher with Lero, the Science Foundation Ireland Research Centre for Software and a member of Lero's OSPO team. Clare was the inaugural Executive Director... Read More →
avatar for Jacek Plucinski

Jacek Plucinski

Technology Transfer Officer, University of Luxembourg
Jacek Plucinski is a technology transfer professional and open source strategist at SnT, University of Luxembourg. He leads SnT’s FOSS (OSPO) activities, manages IP for software assets, licensing and the Venture Program, and has driven key digital transformation projects including... Read More →
Thursday October 8, 2026 15:50 - 16:30 CEST
South Hall 1 A (Floor 1)
 
Friday, October 9
 

11:05 CEST

From Using To Leading: How a Grid Operator Leverages Open Source Strategically - Jonas van den Bogaard, Alliander
Friday October 9, 2026 11:05 - 11:45 CEST
As the energy system transitions into a highly digital, data-driven ecosystem, grid operators face mounting complexity, rising costs, and increasing pressure to deliver scalable and future-proof solutions. In this context, open source is no longer a technical preference. It is becoming a strategic necessity.

In this session, Alliander shares how it has repositioned open source as a key enabler of its digital strategy. We show how a clear vision helps maximize public value, accelerate innovation, strengthen digital sovereignty, and improve transparency, while maintaining control over long-term costs.

We introduce three guiding principles: Open Source First, Building Together, and Confidence in Openness. We also highlight practical implications, from embedding open source in procurement to actively contributing and opening internal solutions.

This session offers a concrete example for executives on how to move from ad hoc use of open source to a coherent, organization-wide strategy. Reducing duplication, optimizing investments, and strengthening collaboration across the energy ecosystem, including within LF Energy.
Speakers
avatar for Jonas van den Bogaard

Jonas van den Bogaard

Open Source Office Lead, Alliander N.V.
Jonas van den Bogaard is a Digital Strategy Lead at Alliander, a distribution system operator (DSO) in the Netherlands. Alliander provides reliable, affordable, and accessible energy transport and distribution to a large part of the Netherlands. Open source has proved to be an enabler... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 1 A (Floor 1)

11:55 CEST

What Hides Below 10,000+ SBOMs of a Foundation - Mario Fahlandt, Kubermatic
Friday October 9, 2026 11:55 - 12:15 CEST
It all started with the simple question: "Do we have all exceptions for license dependecies for all the projects?"

As you can imagine this is not a question most organizations can answer out of the blue.
To solve this we started not only generating SBOMS for every single project in the CNCF., but also every Subproject that has a release.
Along the way we hit every wall: inconsistent release processes, license resolution dead ends, CVE matching at scale, and the discovery that generation is maybe 20% of the problem.
We will dig into the full pipeline we built. Automated SBOM generation at scale, auto discovery of Repositories, experimenting with differnet SBOM generation tools, hitting Git limits, license enrichment via deps.dev and ClearlyDefined, vulnerability cross-referencing via OSV, and OpenVEX for suppression.
After we finished this we realized that 10,000+ SBOMs are useless if you cannot search, query, or govern them. So we built an open source toolchain for the whole thing.

You will learn how to build a toolchain for Supply Chain at a sclae that supports a foundation and you can also use in organizatiosn that is fully Open Source and Apache 2 licensed.
Speakers
avatar for Mario Fahlandt

Mario Fahlandt

Customer Delivery Architect, Kubermatic
Mario Fahlandt is a CNCF Technical Oversight Committee member, SIG ContribEx co-chair, and Kubernetes AI Conformance subproject lead. He maintains cncf/sbom, the project generating SPDX SBOMs for every CNCF release, and created SeeBOM, an open-source SBOM governance platform now applying... Read More →
Friday October 9, 2026 11:55 - 12:15 CEST
South Hall 1 A (Floor 1)

12:15 CEST

The Hard Limits of a (de)-centralized OSPO - Sebastian Grüner, E.ON Digital Technology & Benjamin Rilz, E.ON Digital Technology GmbH
Friday October 9, 2026 12:15 - 12:35 CEST
Starting up an OSPO is not an easy task - let alone for 300+ companies. That's the scale and problem space we face in the highly federated and distributed enterprise of E.ON.

One of Europe's biggest energy utility provider has it all: critical infrastructure, regulations, services for millions of customers, purpose built hardware, SaaS businesses, an unfathomable amount of suppliers and engineers all over the place.

So before we could even start with our own ideas about the OSPO management we needed to get a hold of the status quo at E.ON for any kind of engineering and business operations. Two years after starting the OSPO we're far from done doing that yet, but we already established quite a bunch of successful initiatives.

We'll present our idea of an Hub-and-Spoke-OSPO, targeted initiatives for distinct parts of the business, curing pain points, building recurring collaborations within the enterprise and how to become more visible as 2-person-OSPO with nearly 80.000 coworkers.
Speakers
avatar for Sebastian Grüner

Sebastian Grüner

Open Source Consulting Manager, E.ON Digital Technology
Leads the OSPO initiative at the IT subsidiary of E.ON, helping transform our grid for a carbon neutral future. Before that he worked 13 years as a journalist and editor covering Open Source - technology and software as well as the sociopolitical influence of the projects and their... Read More →
avatar for Benjamin Rilz

Benjamin Rilz

Junior Tech Consultant, E.ON Digital Technology GmbH
I work in the Open Source Program Office at E.ON Digital Technology GmbH, where I focus on connecting the Open Source ecosystems with practical business needs in the energy sector. I have already attended several Linux Foundation conferences, but I haven’t given a talk yet. In this... Read More →
Friday October 9, 2026 12:15 - 12:35 CEST
South Hall 1 A (Floor 1)

14:00 CEST

OpenChain in Central and Eastern Europe: Year One - Vladimir Slavov & Nikola Babadzhanov, Bosch
Friday October 9, 2026 14:00 - 14:20 CEST
One year ago, we created the OpenChain Meridian 22 Work Group for Central and Eastern Europe. In this year, our community has grown to include members from Poland, Hungary, Finland, Romania, Bulgaria, Greece, and other countries. We promoted OpenChain and our WG formally at open source and security events in Serbia, Slovenia, and Bulgaria, and informally in other parts of Europe and the world. We work in close collaboration with other open source communities to organize free events across Europe.

This talk is a retrospective on this past year of expanding the OpenChain community in the region. We will showcase the interesting topics we focus on in our WG, and share the lessons we learned along the way. We would like to use the talk to promote the WG locally.

The first part of the talk will focus on the journey: how we launched the OpenChain Meridian 22 WG, our promotion activities, and the topics we have tackled so far.

The second second part, about the takeaways: what makes this region special, why we received attention mostly from security communities, and other such curiosities.

The last part will be an overview of the co-located event we are organizing with the community.
Speakers
avatar for Vladimir Slavov

Vladimir Slavov

Open Source Consultant, Bosch
Vladimir is a lawyer and a programmer. He works at Bosch's Open Source Program Office, focusing on open source management and compliance. He is an AWS Certified Solutions Architect Associate, an AWS Certified AI Practitioner, and an AWS Certified Cloud Practitioner. He co-chairs the... Read More →
avatar for Nikola Babadzhanov

Nikola Babadzhanov

Open Source Management Consultant, Bosch
Nikola Babadzhanov, a Bosch Open Source Consultant since 2022 and a member of the Bosch OSPO, focusing on software and Open Source management. He expertly applies his FinTech regulatory compliance experience to the unique challenges of Open Source compliance.

Formerly the chair of a Bosch group on secure and compliant containers, Nikola is a dedicated OpenChain Ambassador, a committer on the Eclipse Apoapsis project, and an active member of the OpenChain SBOM, AI, and Tooling work groups... Read More →
Friday October 9, 2026 14:00 - 14:20 CEST
South Hall 1 A (Floor 1)

14:20 CEST

Are Open Source Licenses for AI Models a Hallucination? - Jimmy Ahlberg, Ericsson & Eleftheria Stefanaki, Nokia Technologies
Friday October 9, 2026 14:20 - 14:40 CEST
For decades, the Open Source Software world has run on a simple, elegant legal hack: standard open-source licenses (like GPL, BSD, or Apache 2.0) use copyright law to enforce openness and collaboration. But as the industry shifts to AI models are we are hitting a catastrophic legal wall? AI models and weights aren't code, they aren't traditional "data" either. Is the licensing regimes we have been reliant on for so long no longer an adequate solution for how to license AI Models and wights when we want to make them available and keep them as Open Source, and if so why do we keep on licensing them this way?

This panel hopes to brings together experts from various fields and industries to discuss some of the challenges and potential risks you may run into then using or sharing AI models and wights under Open Source licenses, and explore some high level ideas of what mechanisms could be used instead of "traditional" Open Source licenses to keep the openness and collaboration we all depend on to further innovation.
Speakers
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
avatar for Eleftheria Stefanaki

Eleftheria Stefanaki

FOSS Legal Counsel, Nokia Technologies
I am a lawyer from Greece, specialized in technology and passionate about open source. I have started my 'open source journey' in Ericsson, assisting and participating in the activities and day-to-day of the OSPO since 2022. Currently, I am the FOSS Legal Counsel for Nokia Technologies... Read More →
Friday October 9, 2026 14:20 - 14:40 CEST
South Hall 1 A (Floor 1)

14:50 CEST

CRA Compliance Paths and Where the Real Responsibility Sits - Madalin Neag, OpenSSF/The Linux Foundation
Friday October 9, 2026 14:50 - 15:30 CEST
The EU CRA is now law, yet confusion persists across the software ecosystem. Many developers still fear personal liability for upstream contributions, while organizations struggle to understand what compliance actually requires.
This talk clarifies the four CRA compliance pathways: Self-Assessment, Standards, 3rd party Conformity Assessment, and the EUCC, and explains how they apply across the software supply chain.

We demystify the CRA’s approach to open source, focusing on OSS stewards such as foundations and legal entities, and their limited obligations compared to manufacturers. A key message: upstream contributors and individual maintainers have no direct CRA compliance responsibilities.
We also examine supply chain security implications, including the need for stronger upstream-downstream collaboration, better dependency transparency, and clearer security ownership at integration points. Misinterpretation of CRA roles risks shifting compliance burden incorrectly upstream, undermining ecosystem resilience.
Attendees will leave with a clear understanding of CRA responsibility boundaries, compliance routes, and the role of open source in a secure European software supply chain.
Speakers
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF/The Linux Foundation
Madalin is the EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 1 A (Floor 1)

15:40 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them.

The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the same problem: we're scanning and rescanning the same packages for the same (or similar) data.

That redundancy has real costs. Compute, maintainer time, and contributor energy spent on work that's already done is capacity not spent on expanding coverage, improving accuracy, or hardening infrastructure.

It's time to build together. This talk is a conversation about what it would look like to join forces on open software supply chain data, produced with open source tools and backed by open standards with shared infrastructure and aligned and unlocked datasets for wider usage. We'll explore where our data models overlap, where they diverge, and what collaboration would require, so we all can get sustainable, high-quality, and open supply chain data at ecosystem scale faster together.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 1 A (Floor 1)

16:30 CEST

Running OSPOs at Scale: Hard-Won Lessons From Germany Industry - Thomas Steenbergen, OSSYN & Helio Chissini de Castro, Cariad
Friday October 9, 2026 16:30 - 17:10 CEST
Most organizations know they should manage open source strategically and efficiently. Few know how to actually do it when you're moving fast, resources are tight, and a supply chain incident can land on the front page.

Over the past several years, we've helped build and run Open Source Program Offices across multiple large German automotive and technology organizations. This session distills what actually worked - and what didn't.

We'll share concrete lessons on: getting buy-in from C-level to developer teams; surviving and learning from supply chain security incidents; scaling compliance without drowning engineers in process; using AI to cut OSPO workflow overhead; and growing open source contribution and compliance culture.

Along the way, we'll show how we used OSS Review Toolkit (ORT), a Linux Foundation project, as the automation backbone - and what we learned making it work in large, regulated industries.

You'll leave with a clearer picture of what it takes to scale open-sourcing and compliance in a regulated industry, and the mistakes worth skipping.
Speakers
avatar for Thomas Steenbergen

Thomas Steenbergen

Principal Consultant / ORT co-founder and maintainer, OSSYN
Thomas Steenbergen specializes in strategic open source management, helping organizations align their practices with business goals. An expert in open source adoption, community building, and compliance (including SBOMs), he is freelance consultant currently working for OSPOs of CARIAD... Read More →
avatar for Helio Chissini de Castro

Helio Chissini de Castro

Software Tooling Lead, Cariad
Helio Chissini de Castro has 25 years of open source experience in multiple areas, from contributions to community management and entire project design. His entire professional life was around bring open source to the most possible areas. On recent years, Helio has an ongoing effort... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 1 A (Floor 1)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.