Loading…
June 23 - 25, 2025
Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (UTC/GMT -6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Wednesday June 25, 2025 2:30pm - 2:50pm MDT
For years, the supply chain security community has been working hard to generate security metadata about repositories, software builds, vulnerability reports, releases, and SBOMs that describe how software is composed.

Transparent build processes with visible supply chains are great, but all that information has been remarkably difficult to use. Until now!

Meet AMPEL, the Amazing Multi-Purpose Policy Engine. Ampel (https://github.com/carabiner-dev/ampel) is the missing piece in the supply chain ecosystem: an open source policy engine that natively understands in-toto attestations, verifies keyless Sigstore signatures and understands any attestation predicate type. 

Ampel is embeddable: it can look into SBOMs and warn about bad dependencies, understand security scans and gate builds when vulnerabilities are present, or stop artifacts from publishing when they don't meet security frameworks. 

Ampel is slowly building an ecosystem: Starting with the bnd attester, the Ampel universe has tools that can work across the SLDC to secure CI/CD systems.

In this talk, we'll explore with practical examples how Ampel can ensure compliance of a hardened pipeline through verifiable evidence.
Speakers
avatar for Adolfo García Veytia

Adolfo García Veytia

Staff Software Engineer, Carabiner Systems, Inc
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Wednesday June 25, 2025 2:30pm - 2:50pm MDT
Bluebird Ballroom 3B
  cdCon
Log in to leave feedback.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link