Loading…
June 23 - 25, 2025
Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (UTC/GMT -6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Type: Operations Management clear filter
Monday, June 23
 

3:35pm MDT

Sponsored Session: Operational Data Stores for Financial Risk Mitigation - Bryce Curtis, Discover Financial Serves
Monday June 23, 2025 3:35pm - 4:15pm MDT
Managing risk is always top-of-mind in the financial industry and mitigation is essential to reduce it. One significant risk is the software supply chain that represents the complex network of processes, tools and stakeholders involved in the development, distribution and deployment of software throughout the entire software development lifecycle (SDLC). Operational Data Stores (ODS) can be used to help mitigate the risk associated with software running in any enterprise. They accomplish this by aggregating and correlating operational data from across the disparate systems and tools that comprise the SDLC pipeline into a single, standards-based software bill of materials (SBOMs) data model. By providing real-time data access for investigational queries and composite views of all applications for stakeholders and regulatory agencies, risk associated with the full lifecycle of software management and consumption can be mitigated. Join this session to see how Discover is embracing Operational Data Stores and how it can apply to the broader enterprise community.
Speakers
avatar for Bryce Curtis

Bryce Curtis

Expert Solution Innovator, Discover Financial Serves
Bryce Curtis is an Expert Solution Innovator in the Discover Financial Serves R&D Lab, where he is a technology leader and researcher for numerous emerging technologies and projects. Bryce has been active in the open source community for many years and believes that open source enables... Read More →
Monday June 23, 2025 3:35pm - 4:15pm MDT
Bluebird Ballroom 3H
 
Wednesday, June 25
 

11:00am MDT

Finally! A New Trademark Policy - Rebecca Rumbul & Gracie Gregory, The Rust Foundation
Wednesday June 25, 2025 11:00am - 11:40am MDT
Refreshing long-standing policies in OSS communities can be a long and difficult process. Last year at OSS Summit NA, we discussed getting to the mid-point in our journey in developing a new trademark policy for the Rust community. Following a lot of further work, consultation, and iteration, and final board approval, we are now able to reflect on the whole process of redeveloping a legal policy with an OSS community, the pitfalls, challenges, and paths to success.
Speakers
avatar for Rebecca Rumbul

Rebecca Rumbul

CEO & Executive Director, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
avatar for Gracie Gregory

Gracie Gregory

Director of Communications & Marketing, The Rust Foundation
Wednesday June 25, 2025 11:00am - 11:40am MDT
Bluebird Ballroom 3D
  Operations Management
  • Audience Experience Level Any

11:55am MDT

In From the Cold - Open Source as Part of Mainstream Software Asset Management - Shane Coughlan, The Linux Foundation
Wednesday June 25, 2025 11:55am - 12:35pm MDT
Software Asset Management (SAM) provides a way to manage software across small, medium and large entities. It is often seen as a way of addressing licensing or for making sure company staff are using permitted software applications and versions.

Open source has traditionally been divorced from SAM, which was focused on proprietary software solutions. Partly this was due to practical matters like different licensing schemes, and partly it was an artifact of separate paths of evolution.

However, in recent years open source has increasingly adopted approaches to licensing, security and other challenges that mirror SAM. Examples include the use of standards like ISO/IEC 5230 for licensing and ISO/IEC 18974 for security, of implementation standards like ISO/IEC 5962 for Software Bill of Materials.

As a consequence, open source is now more closely aligned with SAM. This talk will examine what that means for open source management overhead today, and where it will take us in the future. This talk is intended to equip people in open source strategy, legal and team leadership to navigate changes as smoothly as possible.
Speakers
avatar for Shane Coughlan

Shane Coughlan

OpenChain General Manager, The Linux Foundation
Shane Coughlan is an expert in communication, security and business development. His professional accomplishments include spearheading the licensing team that elevated OIN into the largest patent non-aggression community in history and establishing the first global network for open... Read More →
Wednesday June 25, 2025 11:55am - 12:35pm MDT
Bluebird Ballroom 3D
  Operations Management

2:10pm MDT

Using SBOMs for Linux Foundation Projects - Jeff Shapiro, The Linux Foundation & Gary O'Neall, Source Auditor Inc.
Wednesday June 25, 2025 2:10pm - 2:50pm MDT
Last year we introduced the LF-SBOM, which we are now generating for many projects. Today we will provide an update on this important effort to provide SBOMs for most critical LF projects. We will review the work done to date, and go into more detail on how to use the LF-SBOM specification. We will give real world concrete examples on how to use our SBOM to generate a Security Vulnerability report, and how to generate a report of open source licenses. We will also discuss how to use our SBOMs to meet new regulations (e.g. US CISA and EU CRA) when delivering software to the government sector, and how to use our SBOM as an example when you create one for your own project.
Speakers
avatar for Jeff Shapiro

Jeff Shapiro

Director of License Scanning, The Linux Foundation
Jeff Shapiro is the Director of License Scanning for The Linux Foundation. He has 30 years of experience in the software industry, including 10 years in software auditing, open source scanning, and training developers in OSS license compliance.
avatar for Gary O'Neall

Gary O'Neall

Founder and Principal Consultant, Source Auditor Inc.
Gary is a contributor to the Software Package Data Exchange® (SPDX™) - an open standard for communicating software bill of material information, including components, licenses, copyrights, and security references. Gary has contributed several open source tools.Gary O’Neall is... Read More →
Wednesday June 25, 2025 2:10pm - 2:50pm MDT
Bluebird Ballroom 3D
  Operations Management

3:05pm MDT

Let's Play AI Supply Chain Candyland! - Sarah Evans, Dell Technologies & Christopher Robinson, OpenSSF - The Linux Foundation
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
Picture the WHOLE software supply chain, beginning to end; it's a little like that olde tyme classic, "Candyland".

Designed NOT with preschoolers in mind, AI Supply Chain Candy Land is for everyone interested in learning about the software supply chain for AI/ML. Travel through exotic locations like The Peppermint Forest of swirly-twirly dependencies, The Fudgy Swamp of Compliance, and much more!

AI/ML is a fast-moving space within technology. However, everything we've learned in software engineering of the last few decades ALSO applies to this "new" world of AI/ML. We'll apply traditional software supply chain security techniques and, wherever able, tools to help developers and consumers win AI Supply Chain Candyland.

Through an enjoyable and colorful game, with useful examples taken from standards and frameworks, the audience will have a better appreciation and ability to apply supply chain security concepts and tools to the development and support of AI/ML-based solutions.
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, OpenSSF
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah is a security innovation researcher, leveraging diverse experiences as an IT and security practitioner to improve security by design in emerging technologies. Prior to Dell, Sarah has had roles at in the finance, defense, manufacturing and education industries. Sarah also contributes... Read More →
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
Bluebird Ballroom 3D
  Operations Management

4:20pm MDT

How To Stay Compliant With and Take Benefits From the EU CRA (Cyber Resilience Act) - Roman Zhukov, Red Hat
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
The EU Cyber Resilience Act (CRA) aims to safeguard European consumers and at first glance it targets only the EU market. But in fact the entire OSS ecosystem falls under its scope as CRA creates mandatory cybersecurity requirements for vendors, distributors, integrators, even enterprise consumers and, in fact, the entire open-source ecosystem by introducing terms like “Manufacturer”, “Steward”, “Individual developer” among others. So, how to ensure **you** stay compliant?

I’ll cover what we, as part of the various working and regulatory expert groups, are doing to help the entire open-source community navigate the actual requirements. We’ll explore how these roles are played together by the leading industry players (yes, revealing some non-trivial scenarios) and what best practices and tools can be used right away for your organization or by you as an individual contributor. Finally, let’s discuss how we together should turn CRA into an opportunity to make open-source better for all.
Speakers
avatar for Roman Zhukov

Roman Zhukov

Principal Security Community Architect, Red Hat
Practicing Cybersecurity expert, engineer and manager (15+ years), (ISC)2 CC (Certified in Cybersecurity). Currently - Principal Security & Community Architect at Red Hat. Ex. - Head of Product Security & Privacy for Data Center & AI SW at Intel. Roman has broad experience from security... Read More →
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
Bluebird Ballroom 3D
  Operations Management
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.