Loading…
June 23 - 25, 2025
Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (UTC/GMT -6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Type: Wildcard clear filter
arrow_back View All Dates
Tuesday, June 24
 

11:00am MDT

Panel Discussion: The Technical Talent Market in 2025: Fortifying for AI, Cybersecurity, and Regulatory Compliance - Anna Hermansen, Clyde Seepersad & Adrienn Lawson, The Linux Foundation & Christopher Robinson, OpenSSF
Tuesday June 24, 2025 11:00am - 11:40am MDT
For the past three years, LF Education has partnered with LF Research to produce a yearly State of Tech Talent report surveying hiring and training managers to capture trends in the IT talent market. The 2025 study, which will go live at Open Source Summit North America, explores AI’s impact on organizational operations and developers; the fastest-growing areas of job responsibility; and compliance shifts from policies like the Cyber Resilience Act. In this session, the LF Research team will host a discussion of this year’s study findings, with panelists from LF Education and OpenSSF sharing their expertise on hiring and training to address cybersecurity concerns, regulatory compliance, AI, and more. In discussing the findings of the study, this session will describe how the community is grappling with resourcing amidst the new and shifting priorities in this landscape, from AI to Cybersecurity to platform engineering. The session will deliver insight on how the open source community can take the findings of the study to fortify its organizations and people for the market in 2025 and beyond and maintain relevance among economic, regulatory, and technological changes.
Speakers
avatar for Adrienn Lawson

Adrienn Lawson

Director of Quantitative Research, The Linux Foundation
Adrienn serves as Director of Quantitative Research at the Linux Foundation, where she leads data-driven initiatives to understand open source ecosystems. With expertise in social data science from the University of Oxford and a background spanning academic and governmental research... Read More →
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Anna Hermansen

Anna Hermansen

Researcher and Ecosystem Manager, The Linux Foundation
Anna is the Ecosystem Manager for LF Research where she supports end-to-end management of the department's research projects. She has conducted qualitative and systematic review research on the integration of technologies to better support health data sharing. Her interests lie at... Read More →
avatar for Clyde Seepersad

Clyde Seepersad

SVP, The Linux Foundation
LF exec in leading the education team
Tuesday June 24, 2025 11:00am - 11:40am MDT
Bluebird Ballroom 2E
  Wildcard, Open Source Leadership
  • Audience Experience Level Any

11:55am MDT

Wait, So Now You're Telling Me We Need FGA? - Carla Urrea Stabile, Auth0 by Okta
Tuesday June 24, 2025 11:55am - 12:35pm MDT
When building an application, we often start with simple requirements: “Just make sure only the admin can see this page.” Fast forward a few months, and the requirements have grown into a tangled web of roles, attributes, exceptions, and edge cases. Sound familiar?

In this talk, we’ll follow the journey of a fictional project that begins with no access control, progresses to Role-Based Access Control (RBAC), struggles with Attribute-Based Access Control (ABAC), and ultimately finds its footing with Fine-Grained Authorization (FGA). In this process, you’ll learn how OpenFGA addresses the growing complexity of modern applications with a relationship-based model that’s both flexible and scalable.
Speakers
avatar for Carla Urrea Stabile

Carla Urrea Stabile

Senior Developer Advocate & Software Engineer, Auth0 by Okta
Carla is a software engineer and developer advocate at Auth0 by Okta. She’s a language agnostic developer but enjoys working with Ruby and Python. When she’s not working you can find her going on walks with her dogs, hiking or going on a bike ride.
Tuesday June 24, 2025 11:55am - 12:35pm MDT
Bluebird Ballroom 2E
  Wildcard

2:10pm MDT

Valkey in Telecom: Leveraging Open Source for Unique Needs and Greater Community Benefits - David Östman & Viktor Söderqvist, Ericsson Software Technology
Tuesday June 24, 2025 2:10pm - 2:50pm MDT
The telecom industry constantly evolves to meet the demands of modern communication.
As a supporter of the Linux Foundation Valkey project, this presentation will explore other ways to utilize Valkey compared to many cloud providers, and the benefits this brings to the community and the project itself.

We will discuss the technical aspects of Valkey's use in telecom, drawing from insights for the advantages of public forks managed by foundations, leading to faster and more expansive development.

Our company was one of the founding supporters of Valkey, and Viktor Söderqvist is a core maintainer of Valkey. We will cover how we integrate community engagement and governance, David as a manager and Viktor maintainer and our collaborative efforts together.

We'll highlight our contributions to Valkey, and the discussions that led to our strategic pivot and fork and creation Valkey.

We will also present unique requirements in telecom that has been added to Valkey, and demonstrate how these requirements also benefit the broader project, with features like downgrade mechanisms and key hash improvements for higher performance.
Speakers
avatar for David Östman

David Östman

General Manager Ericsson Software Technology Sweden, Ericsson
David is the General Manager of Ericsson Software Technology (EST) Sweden, leading a dedicated team of engineers developing open source software on projects like Linux, Yocto, and Valkey. With over 25 years of experience in the telecommunications industry, David began his career at... Read More →
avatar for Viktor Söderqvist

Viktor Söderqvist

Open source dev, Ericsson Software Technology
Viktor is an open source developer at Ericsson, contributing to several projects. The last few years, he was contributing to Redis, but recently his focus has been on Valkey, the open source fork of Redis, which he together with a few more active contributors forked and now maint... Read More →
Tuesday June 24, 2025 2:10pm - 2:50pm MDT
Bluebird Ballroom 2E
  Wildcard
  • Audience Experience Level Any

3:05pm MDT

Solving the Phantom Dependency Problem for Python Packages - Seth Larson, Python Software Foundation
Tuesday June 24, 2025 3:05pm - 3:45pm MDT
Endor Labs coined the term "Phantom Dependency Problem" to describe dependencies that are bundled into software packages but not represented in the package metadata. This is common in many software package ecosystems, but it is most prevalent in the Python package ecosystem (PyPI) where many packages include compiled C, C++, and Rust dependencies.

Bundled software not being included in package metadata is meaning means that software composition analysis (SCA), SBOM, and vulnerability scanning tools are not able to detect the bundled software. This can cause vulnerabilities to be missed and make.

The Security Developer-in-Residence at the Python Software Foundation, Seth Larson, worked on solving to the Phantom Dependency problem for Python packaging, involving work on standards and tooling.

By the end of this session attendees will understand the Phantom Dependency problem, how it relates to Python and other packaging ecosystems, how SBOM and SCA tools work, and what work was done to make bundled dependencies measurable and what that means for users.
Speakers
avatar for Seth Larson

Seth Larson

Security Developer-in-Residence, Python Software Foundation
Seth is the Security Developer-in-Residence at the Python Software Foundation working to improve the security posture of the Python ecosystem. Seth maintains widely used open source Python projects like urllib3, truststore, and Requests.
Tuesday June 24, 2025 3:05pm - 3:45pm MDT
Bluebird Ballroom 2E
  Wildcard

4:20pm MDT

Your Silent Software Saboteur: Open Source Malware - Brian Fox, Sonatype
Tuesday June 24, 2025 4:20pm - 5:00pm MDT
Weaponized open source components are silently infiltrating software supply chains, evading detection, and leaving organizations vulnerable to devastating attacks. Brian Fox, Co-founder and CTO of Sonatype, will pull back the curtain on this invisible threat, diving into the rise of malicious components that proliferate at an unprecedented rate.

Discover the stealthy tactics used to infiltrate networks, masquerading as legitimate software, and understand why traditional security solutions are failing. This session will provide the knowledge and tools to proactively protect software supply chains, blocking malicious components before they wreak havoc, and fortify defenses against this invisible and growing enemy.
Speakers
avatar for Brian Fox

Brian Fox

Co-founder and CTO, Sonatype
Co-founder and CTO, Brian Fox is an OpenSSF Governing Board member, a member of the Apache Software Foundation and former Chair of the Apache Maven project. As a direct contributor to the Maven ecosystem, including the maven-dependency-plugin and maven-enforcer-plugin, he has over... Read More →
Tuesday June 24, 2025 4:20pm - 5:00pm MDT
Bluebird Ballroom 2E
  Wildcard
  • Audience Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -