Loading…
June 23 - 25, 2025
Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (UTC/GMT -6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Type: cdCon clear filter
arrow_back View All Dates
Wednesday, June 25
 

11:00am MDT

From CDEvents To Actions: Designing the Workflow Conductor - Dadisi Sanyika & Ben Powell, Apple
Wednesday June 25, 2025 11:00am - 11:20am MDT
The CDEvents specification has been around for some time but what are "we" doing with it? This talk peels back the layers of our journey from CDEvents to the engineering design of a "Workflow Conductor". We will examine how specific events can be translated into actionable steps, enabling the Workflow Conductor to manage and coordinate diverse CI/CD tools. The focus will be on how the declaration of intent is tracked across tools, maintaining a consistent and auditable process. Join us to discover the technical underpinnings of this system and learn how it can transform your software delivery pipeline.
Speakers
avatar for Dadisi Sanyika

Dadisi Sanyika

Engineering Manger, Apple, Inc.
I am Board Chair for the Continuous Delivery Foundation (Linux sub-foundation) and lead a team of engineers at Apple dedicated to improving the Continuous Deployment experience for teams and the community. Our contributions are focused on extending scalability and multi-tenant capabilities... Read More →
avatar for Ben Powell

Ben Powell

Software Engineer, Apple
Ben is a software engineer at Apple for the Spinnaker team with previous experience at AWS for the AWS SDK and ECS team. He has contributed to various different tools, services, and proposals through the years, governs the Cloud SIG for Spinnaker, and is an active participant for... Read More →
Wednesday June 25, 2025 11:00am - 11:20am MDT
Bluebird Ballroom 3B
  cdCon

11:20am MDT

Event Provenance Registry: Continuous Delivery Events for the Electric Sheep - Brett Smith, SAS Institute, Inc.
Wednesday June 25, 2025 11:20am - 11:40am MDT
What if you got a second chance to build an Event Driven Provenance service? In this talk I will cover the decision to start over, rewrite, and Open Source the Event Driven system we built in house. In the process of covering the things we changed and the things we kept I tell a few war stories. Add in what needed to be improved and what we left behind. I will talk about our involvement in the CD Foundation and how the new system can leverage CDEvents and help with SBOM storage and retrieval. Demo and Discussion included dependent on time allotment.
Speakers
avatar for Brett Smith

Brett Smith

Distinguished Software Developer, SAS Institute, Inc.
Software Architect/Engineer/Developer with 25+ years of experience. Specialties: Event Driven Automation, Continuous Integration/Delivery/Testing/Deployment, Supply Chain Security Expertise: Linux, packaging, and tool design. Currently Engineering and Securing the Supply Chain... Read More →
Wednesday June 25, 2025 11:20am - 11:40am MDT
Bluebird Ballroom 3B
  cdCon
  • Audience Experience Level Any
  • Session Slides Yes

11:55am MDT

Navigating Compliance: What Developers Can Learn From Driving - Kadi McKean & Charlie Jones, ReversingLabs
Wednesday June 25, 2025 11:55am - 12:15pm MDT
When driving on a highway, you have to follow the rules of the road—some apply to everyone, while others only apply to commercial drivers. Open source maintainers and software publishers face a similar divide regarding regulatory compliance.

While software manufacturers must meet extensive legal and security obligations, open source maintainers often assume these regulations do not apply directly to them—but do they? In this talk, we’ll separate fact from fiction by breaking down what rules like the EU Cyber Resilience Act require from maintainers versus software vendors.

We’ll explore the limited enforceable obligations for open source projects, including secure development policies and vulnerability reporting, and discuss when (if ever) these rules impact maintainers. By understanding these distinctions, open source contributors can make informed decisions about risk, responsibility, and collaboration with commercial software teams—without unnecessary compliance burdens.
Speakers
avatar for Kadi McKean

Kadi McKean

Community Manager, ReversingLabs
Kadi is passionate about the DevOps / DevSecOps community since her days of working with COBOL development and Mainframe solutions. At ReversingLabs she collaborates with developers and security researchers to help entities prioritize their open source risk, reduce technical debt... Read More →
avatar for Charlie Jones

Charlie Jones

Director of Product Management, ReversingLabs
Charlie is a Software Assurance Evangelist with 7 years of experience in providing strategy and transformation services for cyber security, third party risk, and IT audit programmes of both Fortune and FTSE 100 companies across all 3 lines of defence. Charlie specializes in helping... Read More →
Wednesday June 25, 2025 11:55am - 12:15pm MDT
Bluebird Ballroom 3B
  cdCon
  • Audience Experience Level Any

12:15pm MDT

Not Just Ticking a Box ☑️ Establishing Trust in Artifacts with Provenance 🔐🔗 - Andrew McNamara & Ralph Bean, Red Hat
Wednesday June 25, 2025 12:15pm - 12:35pm MDT
When you buy something, you might want to know where it was assembled and where its parts came from. Depending on how thorough you are, you might want to know more details about the process. Did it meet some organic criteria? Which quality inspector assessed it? Depending on where you live in the world, you get some human readable version of that information stamped on your packaging or included on the box today.

When you consume a software artifact in production, you might want to know its *provenance*.

In this talk, we’ll explore the activity of checking provenance as a gate to production and look at questions you might want to ask. Where is this artifact from, how was it produced, what checks ran against it, who claims these facts anyways, and more. We’ll look at pre-requisites necessary to answer those kinds of questions by comparing the provenance details exposed by systems like Github Actions, Tekton Chains, and Witness.

Join us for this dive into provenance details and tools. You’ll come away with ideas on both why you should generate provenance attestations and how you can use them to do actually valuable things in the real world - not just tick a compliance checkbox.
Speakers
avatar for Ralph Bean

Ralph Bean

Software Engineer, Red Hat
Ralph is an engineer at Red Hat and member of the Konflux Governance Committee. He's happiest when learning new things, the open source way.
avatar for Andrew McNamara

Andrew McNamara

Senior Principal Software Engineer, Red Hat
Andrew McNamara is passionate about usable CI/CD, security, and DevSecOps, drawing from his experience of building and shipping containerized software at IBM and Red Hat. As a SLSA maintainer, Andrew is helping people identify how to approach and understand supply chain security... Read More →
Wednesday June 25, 2025 12:15pm - 12:35pm MDT
Bluebird Ballroom 3B
  cdCon

2:10pm MDT

Managing Resources To Lower Costs - Mark Waite, CloudBees & Melissa McKay, DevSecOps & MLOps Author/Speaker
Wednesday June 25, 2025 2:10pm - 2:30pm MDT
Do you have a closet that’s overflowing? In order to accommodate your favorite latest wardrobe styles (and to avoid a closet clutter disaster), you might need to let go of those jeans two sizes too small or… gasp! … prune your conference t-shirt collection to a reasonable number.

In the CI/CD world, cleaning out your closet translates in part to activities like pruning artifact repos and limiting bandwidth usage appropriately. Businesses are incessantly looking for ways to trim the fat for leaner, healthier bottom lines, and DevOps operational infrastructure can be a clutter hotspot when it comes to resource expense.

Learn how the Jenkins project has reduced costs with more effective management of its operational resources. We’ll share techniques that we’ve used to identify costs, reallocate resources to reduce those costs, and adapt to changing environments. The Jenkins closet is looking better than ever!
Speakers
avatar for Mark Waite

Mark Waite

Manager, CloudBees
Mark is a member of the Jenkins governance board, maintainer of the Jenkins git plugin, and a long-time contributor to continuous integration and continuous delivery topics.
avatar for Melissa McKay

Melissa McKay

DevSecOps & MLOps Author/Speaker
Melissa is passionate about Java, DevSecOps, CI/CD, and MLOps. She has served on the TSC of the Open Platform for Enterprise AI (OPEA) and the CNCF Governing Board, and regularly shares her knowledge with the community as a developer, speaker, and author. She has been recognized as... Read More →
Wednesday June 25, 2025 2:10pm - 2:30pm MDT
Bluebird Ballroom 3B
  cdCon

2:30pm MDT

Builds You (and Others) Can Trust: Meet the AMPEL Policy Engine - Adolfo García Veytia, Carabiner Systems, Inc
Wednesday June 25, 2025 2:30pm - 2:50pm MDT
For years, the supply chain security community has been working hard to generate security metadata about repositories, software builds, vulnerability reports, releases, and SBOMs that describe how software is composed.

Transparent build processes with visible supply chains are great, but all that information has been remarkably difficult to use. Until now!

Meet AMPEL, the Amazing Multi-Purpose Policy Engine. Ampel (https://github.com/carabiner-dev/ampel) is the missing piece in the supply chain ecosystem: an open source policy engine that natively understands in-toto attestations, verifies keyless Sigstore signatures and understands any attestation predicate type. 

Ampel is embeddable: it can look into SBOMs and warn about bad dependencies, understand security scans and gate builds when vulnerabilities are present, or stop artifacts from publishing when they don't meet security frameworks. 

Ampel is slowly building an ecosystem: Starting with the bnd attester, the Ampel universe has tools that can work across the SLDC to secure CI/CD systems.

In this talk, we'll explore with practical examples how Ampel can ensure compliance of a hardened pipeline through verifiable evidence.
Speakers
avatar for Adolfo García Veytia

Adolfo García Veytia

Staff Software Engineer, Carabiner Systems, Inc
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Wednesday June 25, 2025 2:30pm - 2:50pm MDT
Bluebird Ballroom 3B
  cdCon

3:05pm MDT

cdCon Closing Session - Jeremy Meiss, cdCon Program Chair
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
Closing words from the cdCon Program Chair, Jeremy Meiss, CDF Community Award announcement, and the giveaway of five "CI/CD Design Patterns" books. Afterwards, you'll get the chance to network with members of the CI/CD community.
Speakers
avatar for Jeremy Meiss

Jeremy Meiss

Director, DevEx & DevRel, OneStream Software
Jeremy is a Developer Experience, Developer Relations, and Community leader, formerly the Director of DevRel & Community at CircleCI, and previously at Solace, Auth0, and XDA. With almost 30 years in Tech, Jeremy is active in the DevRel and DevOps communities, and is a co-creator... Read More →
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
Bluebird Ballroom 3B

4:20pm MDT

CDF Networking Space
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
Use this time to chat and connect with anyone from the CI/CD community you might have missed during the conference.
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
Bluebird Ballroom 3B
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Session Slides
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -