Loading…
June 23 - 25, 2025
Denver, Colorado
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Mountain Daylight Time (UTC/GMT -6). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Venue: Bluebird Ballroom 3G clear filter
Monday, June 23
 

11:20am MDT

BoF: Collaboration with Universities and Enterprises OSPO - Sayeed Choudhury, Carnegie Mellon University; Stephanie Liegg, UC Santa Cruz; Nithya Ruff, Amazon; Natali Vlatko, Cisco
Monday June 23, 2025 11:20am - 12:00pm MDT
Join the TODO Group and CURIOSS community for an interactive session where attendees can share use cases on how their organizations are investing in academic research. Explore practices for transferring knowledge from academia and the research community.

We welcome open source managers, OSPO leaders, and other stakeholders from organizations and universities engaged in research or interested to learn more.


Speakers
avatar for Nithya Ruff

Nithya Ruff

Director, Amazon OSPO, Amazon
Nithya is the Head of Amazon’s Open Source Program Office. Amazon’s customers value open source innovation and the cloud’s role in helping them adopt and run important open source services. She drives open source culture and coordination inside of Amazon and engagement with... Read More →
avatar for Stephanie Lieggi

Stephanie Lieggi

Executive Director, CROSS/OSPO, UC Santa Cruz
Stephanie Lieggi is executive director for the Center for Research in Open Source Software (CROSS) and the UC Santa Cruz Open Source Program Office (OSPO). In her current roles she supports the work of academic-based open source projects and enables a sustainable contributor base... Read More →
avatar for Natali Vlatko

Natali Vlatko

Open Source Lead Architect, Cisco
Natali Vlatko (she/her) is an Open Source Lead Architect at Cisco, specializing in open software, policy, and governance. She is a SIG Docs Co-Chair for Kubernetes and a member of the TODO Group Steering Committee. She plays on the fun computer in her spare time. Her academic background... Read More →
avatar for Sayeed Choudhury

Sayeed Choudhury

Associate Dean for Digital Infrastructure; Director of the Open Source Programs Office; Executive Director of Open Forum for AI, Carnegie Mellon University
Associate Dean for Digital Infrastructure, Director of Open Source Programs Office, and Executive Director of the Open Forum for AI.
Monday June 23, 2025 11:20am - 12:00pm MDT
Bluebird Ballroom 3G

1:30pm MDT

Alignment of Community Contributions and Business Goals - How Can Your OSPO Help? - Masae Shida, VMware (Broadcom)
Monday June 23, 2025 1:30pm - 2:10pm MDT
Today it’s nearly impossible to build software without open source. Some projects are massively popular, and quite often used in multiple products within the same organization. But are we all collaborating on these projects in ways that are aligned across the company? Here your OSPO can help your organization work towards the same goals.
Which open source projects are built into your product portfolio? Who in your organization is contributing to these projects? How do you know your contributions are not impeding each other?
Broader involvement should occur in a coordinated and thoughtful manner across the key projects. Having a united front within open source communities will help your organization drive consistent and effective contributions.
The talk will cover:
● How can your OSPO help coordinate contributions across the organization?
● How can you identify your company’s strategic open source projects?
● How can we ensure these projects will continue to be viable and sustainable?
The audience will learn how an OSPO can enable more efficient and effective contributions to open source projects in ways that are aligned with both their business and community goals.
Speakers
avatar for Masae Shida

Masae Shida

Staff Technical Program Manager, VMware (Broadcom)
Masae is a Staff Open Source Program Manager leading the company’s open source business and community strategy alignment. Previously she led numerous programs including large-scale DX/IT transformations as part of M&A at Cisco, security/compliance process implementation and consumer... Read More →
Monday June 23, 2025 1:30pm - 2:10pm MDT
Bluebird Ballroom 3G
  OSPOCon
  • Audience Experience Level Any

2:25pm MDT

The Role of Package Managers as Partners in License and Attribution Compliance - Damián Vicino, Datadog Inc.
Monday June 23, 2025 2:25pm - 3:05pm MDT
Package managers are essential to modern software development, simplifying dependency management but often hiding transitive changes. This has led to large, shifting dependency trees with little oversight.

Despite evolving independently, most package managers follow a similar model: fetching software and metadata. However, the format, quantity, and quality of this metadata vary significantly.

With heterogeneous language stacks on the rise, OSPOs struggle to manage these differences, making compliance an ongoing challenge.

This talk explores different package managers, the compliance data they provide, and highlights good practices from each. Finally, it proposes how the OSPO community can break silos between ecosystems, encouraging convergence on non-language-specific metadata and practices. This, in turn, will streamline compliance work and strengthen the open source ecosystem as a whole.
Speakers
avatar for Damián Vicino

Damián Vicino

Senior Open Source Specialist, Datadog Inc.
Damian Vicino is a Senior Open Source Specialist at Datadog’s OSPO and an Adjunct Research Professor at Carleton University. He began contributing to open source in the early 2000s, leading a local BSD user group and collaborating with a team on five BSDday Argentina events. He... Read More →
Monday June 23, 2025 2:25pm - 3:05pm MDT
Bluebird Ballroom 3G
  OSPOCon
  • Audience Experience Level Any

3:35pm MDT

Open Source as a Business Imperative: Leveraging PEST Analysis for Strategic Alignment - Kazumi Sato & Masayuki Kuwata, Sony Group Corporation
Monday June 23, 2025 3:35pm - 4:15pm MDT
Open source has become a critical component of modern business strategy, yet its importance has often been overlooked in traditional strategic discussions. This presentation demonstrates how PEST analysis can be used to clarify its strategic value.

We validated Sony's history with open source initiatives in electronics, gaming, and film production, this analysis shows how these efforts aligned with favorable external factors. This provides insights into how open source drives innovation and talent acquisition.

Looking forward, this presentation explores how companies can strategically align their open source initiatives with current political, economic, social, and technological trends. This includes understanding the impact of emerging regulations, generative AI, and the evolution of distributed collaboration.

Participants gain valuable insights into the strategic importance of open source and learn how to effectively advocate for open source initiatives within their organizations. This presentation offers practical tips for engaging both management and engineers in open source activities, ensuring that open source becomes a key driver of business success.
Speakers
avatar for Kazumi SATO

Kazumi SATO

Chief Software Engineer, Chief Open Source Strategist, Distinguished Engineer, Sony Group Corporation
Kazumi SATO is a Distinguished Engineer in Sony. He has been working on Linux-based system software for various Sony products. He also has been working on OSS compliance and relationship with communities in Sony Group. Since 2002, when Sony started to use Linux, he has been leading... Read More →
avatar for Masayuki Kuwata

Masayuki Kuwata

Senior Manager, Sony Group Corporation
Masayuki Kuwata is the OSPO leader of Sony Group Corporation since April 2022. Previously worked on developing embedded software for camcorders and cameras. Currently leading the open source strategy across business units. Organizer of Japan OSPO Local Meetup in Japanese, supported... Read More →
Monday June 23, 2025 3:35pm - 4:15pm MDT
Bluebird Ballroom 3G
  OSPOCon

4:30pm MDT

TODO Steering Committee - Management & OSPO Ask Anything - Brittany Istenes, FINOS Ambassador, ToDo Group Steering Committee; Natali Vlatko, Cisco; Georg Kunz, Ericsson; Ashley Wolf, GitHub; Stephen Augustus, Bloomberg L.P.; Annania Melaku, F5
Monday June 23, 2025 4:30pm - 5:10pm MDT
This Ask Anything session connects attendees to the TODO Group Steering Committee. The TODO Group is an open community of practitioners who aim to create, share knowledge and collaborate on best practices on open source management in organizations to run successful Open Source Program Offices.

Members of the steering committee will assist the audience through the best practices, guides, and tools made by and for open source managers to help them in their day-to-day responsibilities, as well as share their first-hand experiences and lessons learned in building and operating OSPOs. Additionally, attendees will learn ways to connect with the TODO Group – the largest OSPO community dedicated to building best practices in open source management. The session will also provide information on accessing OSPO mentorship in their local regions.
Speakers
avatar for Annania Melaku

Annania Melaku

Open Source Program Manager, NGINX part of F5
Annania Melaku is a Technical Program Manager on the Community Team at NGINX, where she focuses on open source strategy and community programs. With a background in software, she brings experience from industries including defense, telecom, and tech. Annania is passionate about building... Read More →
avatar for Georg Kunz

Georg Kunz

Open Source Manager, Ericsson
Georg is a passionate advocate for open source software and a long term contributor to a wide range of open source projects and communities. He currently serves on the Technical Advisory Council (TAC) and the Governing Board of the Open Source Security Foundation (OpenSSF) as well... Read More →
avatar for Ashley Wolf

Ashley Wolf

Director, Open Source Programs, GitHub
Ashley Wolf is the Director of Open Source Programs at GitHub. She runs initiatives and programs to empower developers to be successful with open source. She is also passionate about helping companies participate in the open source community. Prior to joining GitHub, Ashley led the... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect, Office of the CTO, Bloomberg L.P.
Technical Architect, Office of the CTO at Bloomberg
avatar for Brittany Istenes

Brittany Istenes

OSPO Strategist, FINOS Ambassador, ToDo Group Steering Committee Member
Brittany Istenes started off her career as an elementary school educator which then led to a path of tech. Brittany has led advisory councils, special interest groups, open source contributions, community building, InnerSource initiatives and all the gray areas in between. As a FINOS... Read More →
avatar for Natali Vlatko

Natali Vlatko

Open Source Lead Architect, Cisco
Natali Vlatko (she/her) is an Open Source Lead Architect at Cisco, specializing in open software, policy, and governance. She is a SIG Docs Co-Chair for Kubernetes and a member of the TODO Group Steering Committee. She plays on the fun computer in her spare time. Her academic background... Read More →
Monday June 23, 2025 4:30pm - 5:10pm MDT
Bluebird Ballroom 3G
  OSPOCon
 
Tuesday, June 24
 

11:00am MDT

Six Years of Empowering Open Source Communities - Shuah Khan, The Linux Foundation
Tuesday June 24, 2025 11:00am - 11:40am MDT
Growing new talent and attracting new developers is challenging for open source communities. Yet, it is vital to reach out to train the next generation of developers to keep the open source communities healthy and sustainable.

Equitable access to learning resources is a barrier for a significant number of new developers. It isn't easy for new developers to get a start in open source, connect with open source communities and contribute to them. It is equally challenging for employers to find new developers to add to their technical projects.

Shuah Khan will talk about Linux Foundation's six year journey to provide learning resources for new open source developers, opportunities to experts in open source communities to train and mentor the next generation, and make newly trained talent available to prospective employers.
Speakers
avatar for Shuah Khan

Shuah Khan

Kernel Maintainer & Linux Fellow, The Linux Foundation
Shuah Khan is a Kernel Maintainer & Linux Fellow at The Linux Foundation. She is an experienced Linux Kernel developer, maintainer, and contributor. She authored, A Beginner’s Guide to Linux Kernel Development (LFD103) training course. She designed and leads the Mentorship program... Read More →
Tuesday June 24, 2025 11:00am - 11:40am MDT
Bluebird Ballroom 3G

11:55am MDT

Empowering Asian Contributions: The Rise of Regional User Groups in Open Source Communities - Naomichi Shima & Norio Kobota, Sony Group Corporation
Tuesday June 24, 2025 11:55am - 12:35pm MDT
In the vast landscape of the global Open Source community, Asia, despite its significant population, has historically seen limited contributions.
This session will delve into the recent surge in the establishment of regional user group in Japan and their ripple effects across Asia. We will explore the inception and growth of the OpenChain Project's Japan Chapter since 2017, which has catalyzed the expansion of regional communities in China, Korea, and beyond.
We will discuss the motivations driving individuals in these regional communities and highlight the unique characteristics of the OpenChain Japan community. Furthermore, we will examine the collaborative efforts between the Japanese community and other open source communities like the TODO Group, showcasing how these partnerships have amplified their impact.
Through our experiences, we will share insights on the essential elements for fostering successful regional communities in Japan. Additionally, we will introduce messages from the managers of OpenChain and the TODO Group, emphasizing the importance of integrating regional activities with the global open source ecosystem.
Speakers
avatar for Naomichi Shima

Naomichi Shima

Alliance Manager, Sony Group Corporation
Naomichi Shima is OSPO and Alliance Manager in Sony Group Corporation. He chairs the Sony Group Corporation's Open Source Promotion Committee and works to promote open source compliance within the company. He leads the FAQ subgroup of the OpenChain Japan Work Group. He is an English-Japanese... Read More →
avatar for Norio Kobota

Norio Kobota

Senior Open Source Strategist, Sony Group Corporation
Norio Kobota is a Senior Open Source Strategist in Sony Group Corporation. He is the chair of Open Source Software License Committee in Sony and works to improve OSS compliance and relationships with OSS communities. He represents Sony as a board member of OpenChain Project. And... Read More →
Tuesday June 24, 2025 11:55am - 12:35pm MDT
Bluebird Ballroom 3G
  Equity + Inclusion + Accessibility
  • Audience Experience Level Any

2:10pm MDT

Highlighting the AI in AbleIsm - Michelle Frost, JetBrains
Tuesday June 24, 2025 2:10pm - 2:50pm MDT
The origins of artificial intelligence can be traced back to Ancient Greek mythology and philosophy, where early musings on what it means to be human began. Throughout history, these ideas have shaped our understanding of intelligence and influenced our pursuit of creating machines like us. However, this quest often relies on an idealized version of what it means to be “human”, leading to the exclusion of diverse representations and perpetuating ableism. In this talk, we will explore how AI technologies contribute to modern ableism by reinforcing narrow definitions of intelligence and humanity. We will examine the exclusions inherent in these definitions and discuss whom these technologies leave behind and how. By understanding these biases embedded in AI, we can better address its role in society and work towards more inclusive technology.
Speakers
avatar for Michelle Frost

Michelle Frost

AI Advocate, JetBrains
Michelle Frost is an AI Advocate at JetBrains. With over a decade of engineering experience, Michelle holds a Bachelor of Science in Computer Science from UMKC, a Master of Science in Artificial Intelligence from Johns Hopkins University, and is a Microsoft AI MVP. Michelle is also... Read More →
Tuesday June 24, 2025 2:10pm - 2:50pm MDT
Bluebird Ballroom 3G

3:05pm MDT

Scaling Inclusive Open Source: Strategies & Metrics for Building Equitable Communities - Kenyatta Forbes & Sarah Oyetubo, GitHub; Georg Link, Bitergia; Justin Wheeler, Red Hat
Tuesday June 24, 2025 3:05pm - 3:45pm MDT
Open source thrives on collaboration, but who gets to participate, and how? GitHub’s latest Open Source Survey provides key insights into the state of diversity, equity, inclusion, and accessibility (DEIA) in open source communities—revealing persistent challenges and opportunities for change.
In this session, we’ll explore data-backed strategies for fostering inclusivity at scale, blending insights from GitHub’s research with real-world case studies from diverse open source communities.

We’ll cover:
Key findings from GitHub’s Open Source Survey on inclusivity trends, barriers, and participation gaps.

Proven strategies for increasing diversity in open source projects, including best practices from GitHub’s programs and successful open source initiatives.

Lessons from the field: Case studies of communities that have successfully improved inclusion through mentorship, governance changes, and innovative outreach.

Metrics that matter: How to track progress in DEIA efforts without falling into vanity metrics.
Speakers
avatar for Kenyatta Forbes

Kenyatta Forbes

Sr. Program Manager, Open Source Programs, GitHub
Kenyatta Forbes is the Senior Program Manager for the Open Source Programs Team at GitHub, where she leads strategic initiatives to support the growth and sustainability of open source communities. With over a decade of experience in technology and program management, she enjoys fostering... Read More →
avatar for Sarah Oyetubo

Sarah Oyetubo

Sr. Program Manager, DI&B, GitHub
Sarah Oyetubo is a Certified Diversity and Inclusion practitioner and Senior Program Manager of Diversity, Inclusion, and Belonging at GitHub. She has a proven track record for leading people through transformational change, as demonstrated in various strategic and highly visible... Read More →
avatar for Georg Link

Georg Link

Open Source Strategist and Director of Sales, Bitergia
Georg’s mission is to make open source more professional by using community metrics and analytics. Georg cofounded the CHAOSS Project to advance analytics and metrics for open source project health. Georg is an active contributor to several projects and has often presented on open... Read More →
avatar for Justin Wheeler

Justin Wheeler

Fedora Community Architect, Red Hat
Justin is a creative maker. He is best known as an Open Source contributor and Free Culture advocate originally from the United States. Justin has participated in numerous Open Source communities and led different initiatives to build sustainable software and communities for over ten years.In... Read More →
Tuesday June 24, 2025 3:05pm - 3:45pm MDT
Bluebird Ballroom 3G
  Equity + Inclusion + Accessibility
  • Audience Experience Level Any

4:20pm MDT

DEI Is Dead: What Happens Next? - Jennifer "Jen" Madriaga, The LInux Foundation
Tuesday June 24, 2025 4:20pm - 5:00pm MDT
Many organizations, companies, and departments are now eliminating DEI programs, and with this development, you may be asking what happens next. Even though DEI programs may be disappearing, the conversation around what it entails will still exist. How do we frame the conversation now, and what can we do to advocate on behalf of underrepresented groups? I will walk through some ways in which we can move forward. As someone who had to work with a global audience, I found that the term DEI did not always resonate with everyone. From that experience, I had to find ways to discuss the issues that DEI was meant to address, such as disparity in experiences, perceptions around fairness, the need for better communication processes, and psychological safety on teams. We can use these lessons with a global audience that had different histories and cultural contexts to ensure that conversation is relevant for everyone.
Speakers
avatar for Jen Madriaga

Jen Madriaga

Chief of Staff, Events, The Linux Foundation
Jen Madriaga has worked with numerous open source communities for over a decade through her work at Red Hat and the Linux Foundation. She is committed to building healthy and successful communities and interested in creating solutions collaboratively. While at Red Hat, she co-founded... Read More →
Tuesday June 24, 2025 4:20pm - 5:00pm MDT
Bluebird Ballroom 3G
 
Wednesday, June 25
 

11:00am MDT

Implementing Zero Trust in Government Settings: Strategies, Challenges, and Best Practices - Steve Taylor, DeployHub, Inc
Wednesday June 25, 2025 11:00am - 11:40am MDT
With escalating cyber threats and increasing regulatory pressure, government agencies face a critical need to modernize their security strategies. The Zero Trust model—"never trust, always verify"—has emerged as a cornerstone for safeguarding sensitive data and infrastructure. However, implementing Zero Trust in government settings presents unique challenges, including legacy systems, complex compliance requirements, and the need to balance security with operational efficiency. This talk will provide a roadmap for adopting Zero Trust principles in government environments, offering actionable insights to overcome obstacles and ensure mission readiness.
Speakers
avatar for Steve Taylor

Steve Taylor

CTO, DeployHub
Steve Taylor is a visionary and leader in open-source security, DevOps, and securing the software supply chain. Long before “CI/CD” became a buzzword, Steve was designing cutting-edge pipelines for Fortune 1000 companies, redefining how software is built and deployed. His innovative... Read More →
Wednesday June 25, 2025 11:00am - 11:40am MDT
Bluebird Ballroom 3G
  OpenGovCon

11:55am MDT

Securing Software Supply Chains for the Public Good - Daniel Moch, Lockheed Martin & William Crum, SpectroCloud
Wednesday June 25, 2025 11:55am - 12:35pm MDT
Drawing from our experiences within the public sector, we discuss software supply chain security as it pertains to public sector organizations, including the unique risks and challenges they face and how we can all work together to improve the security of the open source ecosystem.
Speakers
avatar for Daniel Moch

Daniel Moch

Staff Software Engineer, Lockheed Martin
For over 20 years, Daniel has worked as a software engineer in the Defense and Aerospace industry. His experience ranges from embedded device drivers to large logistics and information systems. In recent years, he has focused on helping legacy programs adopt modern DevOps practices... Read More →
avatar for William Crum

William Crum

Defense Success Engineer, SpectroCloud
Sergeant William Crum is a U.S. Marine Corps Reservist and software engineer at Spectro Cloud. He serves with the Marine Innovation Unit, driving software modernization within the Marine Corps. In his civilian role, he is a Docker Captain and Senior Defense Engineer at Spectro Cloud... Read More →
Wednesday June 25, 2025 11:55am - 12:35pm MDT
Bluebird Ballroom 3G
  OpenGovCon

2:10pm MDT

From Wait Times To Real-Time: Empowering DPI for Seamless Citizen Engagements With GenAI Agents - Alex Coqueiro, AWS
Wednesday June 25, 2025 2:10pm - 2:50pm MDT
In this session, I will explore how Generative AI agents are becoming a cornerstone of Digital Public Infrastructure (DPI) using open source, reshaping citizen services and empowering governments to deliver more efficient, responsive, and accessible public services. Learn how Generative AI Agents are revolutionizing government websites, offering 24/7 citizen support, and providing real-time assistance across a wide range of public services. With the ability to handle inquiries, process data, and generate personalized responses, these AI agents significantly reduce wait times and streamline interactions, ensuring faster and more seamless communication between citizens and government agencies. We’ll dive into practical applications, from simplifying bureaucracy to enhancing transparency and accountability, and discuss the transformative potential of Generative AI in creating smarter, more inclusive government channels.
Speakers
avatar for Alex Coqueiro

Alex Coqueiro

Head of Solutions Architecture at AWS, AWS
I oversee the Solutions Architects Team. My responsibilities encompass serving as the technical strategist, effectively guiding and influencing customers in Government, Education, Healthcare, and Non-profit sectors on a day-to-day basis through direct and indirect interactions. I... Read More →
Wednesday June 25, 2025 2:10pm - 2:50pm MDT
Bluebird Ballroom 3G
  OpenGovCon

3:05pm MDT

Building Trust Through Proactive Security - Key Parts of the Trusted Software Supply Chain - Przemyslaw Roguski & Ralph Bean, Red Hat
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
As security concerns continue to grow in the software industry, customers seek assurance that the software they rely on is built securely. While applying security patches is essential, it is equally important to understand the proactive measures taken throughout the development process to ensure that our software is built securely.

Red Hat follows a comprehensive Secure Software Development Lifecycle (SDLC) framework to improve software security during the entire software lifecycle. We use an open source end-to-end build and release environment, which uses SLSA framework as a guide for reinforcing and gating the build process to secure and fortify your software supply chain against various threats.

This session will include:
- The key difference between proactive and reactive security measures.
- SDLC objectives and how Red Hat achieves them to meet high security standards.
- Overview of how automated testing and open-source solutions enhance SDLC.
- Proactive vulnerability management during the build lifecycle phase.
- Secure software building with attestation data production, including CSAF/VEX and SBOM.
- Future of AI testing within the software supply chain security.
Speakers
avatar for Przemyslaw Roguski

Przemyslaw Roguski

Principal Product Security Engineer, Red Hat
Przemysław “Rogue” Roguski is a Security Architect at Red Hat who specializes in shift-left security initiatives included in build and release processes. He is focused on the security data improvements, especially security data usability in the vulnerability management and production... Read More →
avatar for Ralph Bean

Ralph Bean

Senior Principal Software Engineer, Red Hat
Ralph is an engineer at Red Hat and member of the Konflux Governance Committee. He's happiest when learning new things, the open source way.
Wednesday June 25, 2025 3:05pm - 3:45pm MDT
Bluebird Ballroom 3G
  OpenGovCon

4:20pm MDT

Trust but Verify: Uncovering the Hidden Risks of Inaccurate SBOMs With JBomAudit - Yue Xiao, Jiyong Jang, Douglas Schales & Dhilung Kirat, IBM Research
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
Software supply chain attacks have surged in recent years, posing significant threats to organizations. In response, Software Bill of Materials (SBOMs)—structured inventories that document software components—have been proposed to enhance supply chain transparency, track dependencies, and manage vulnerabilities. Despite increasing adoption, their correctness and completeness in real-world open-source ecosystems remain largely unexamined. Incomplete SBOMs can result in overlooked vulnerabilities while incorrect dependency may waste resources on non-existent issues.

This talk introduces JBomAudit, an open-source tool to automatically verify Java SBOMs by systematically assessing their correctness and completeness against NTIA minimum requirements. We will cover technical details of JBomAudit, demonstrate how it examines missing and incorrect dependencies, and present findings from our large-scale analysis of over 25,000 Java SBOMs, highlighting the prevalence of non-compliant SBOMs and security implications. We will also discuss common pitfalls in SBOM generation, analyze the root causes of non-compliance, and provide actionable recommendations to improve SBOM quality.
Speakers
avatar for Douglas Schales

Douglas Schales

Senior Technical Staff Member, IBM
Doug Schales is a Senior Technical Staff Member at IBM Research. He has been involved in security research for over 30 years. His interests are in the areas of using generative AI for security, as well as the application of sketch and probabilistic algorithms in security.
avatar for Dhilung Kirat

Dhilung Kirat

Senior Research Scientist, IBM Research
Dhilung Kirat is a Research Scientist in the AI Supply Chain Security group of the Security Research department at IBM T.J. Watson Research Center. Dhilung received his PhD in Computer Science from University of California, Santa Barbara in 2015. His research interests revolve around... Read More →
avatar for Jiyong Jang

Jiyong Jang

Principal Research Scientist, IBM Research
Jiyong Jang is a Principal Research Scientist at IBM Research. His research interests include most areas of computer security, with an emphasis on software and network security. His current research focuses on security analytics to detect advanced threats in complex networking systems... Read More →
avatar for Yue Xiao

Yue Xiao

Research Scientist, IBM Research
Dr. Yue Xiao is a Research Scientist at IBM Watson Research. She earned her Ph.D. from Indiana University Bloomington, focusing on GenAI security, privacy compliance, vulnerability assessment, and supply chain security. She has published in top venues (CCS, Usenix Security, NDSS... Read More →
Wednesday June 25, 2025 4:20pm - 5:00pm MDT
Bluebird Ballroom 3G
  OpenGovCon
  • Audience Experience Level Any
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.