Loading…
Attending this event?
September 16-18, 2024
Vienna, Austria
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central European Summer Time (UTC/GMT +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

SupplyChainSecurityCon clear filter
arrow_back View All Dates
Wednesday, September 18
 

11:00 CEST

Enhancing Artifact Security with GitHub’s Build Provenance and Minder - Fredrik Skogman, GitHub & Radoslav Dimitrov, Stacklok
Wednesday September 18, 2024 11:00 - 11:40 CEST
In the evolving landscape of software development, ensuring the integrity of build artifacts like container images is crucial. In this talk, we'll demonstrate how to use GitHub's Build Provenance API to generate SLSA attestations and create robust policies for your artifacts, verifying their origin and authenticity. We'll examine the contents and significance of these attestations and discuss how to integrate them into your CI/CD pipelines. Additionally, we'll explore using Minder to monitor and enforce these policies across your repositories, ensuring these attestation practices do not degrade over time. We’ll also show how combining these tools can safeguard even in the event of someone else gaining access and pushing a malicious image to your container registry. By the end of this session, you'll have a good understanding of how open source tools like Sigstore, in-toto, SLSA, TUF, and Minder can collectively strengthen the security of the software supply chain. You'll gain practical insights into setting up artifact attestations with GitHub's API and establishing tailored policies with Minder to protect your development processes against vulnerabilities.
Speakers
avatar for Radoslav Dimitrov

Radoslav Dimitrov

Senior Software Engineer, Stacklok
Radoslav Dimitrov is a Senior Software Engineer at Stacklok. He's a maintainer of go-tuf, RSTUF and Minder and is contributing to several other software supply chain projects. His interests include mountain biking, cats, coffees and everything that relates to DIY.
avatar for Fredrik Skogman

Fredrik Skogman

Staff Engineer, GitHub
Fredrik is a Staff Engineer on the Package Security Engineering team at GitHub, where he focuses on software supply chain security. At GitHub he provides technical leadership for standards and tools in the supply chain security space, most recently co-authoring the published npm RFC... Read More →
Wednesday September 18, 2024 11:00 - 11:40 CEST
Room 2.15 (Level 2)

11:55 CEST

Measuring Security Risk: Community Engagement Is the Best Mitigation - Deb Nicholson, Python Software Foundation
Wednesday September 18, 2024 11:55 - 12:35 CEST
When considering open source software that you include in your products, engaging with your upstream is a more robust and resilient way to gauge your security risks than relying on outsourcing your trust modeling to metrics and GitHub stars. Becoming a partner to your upstream community helps you build more secure software and create the relationships you'll need if there's ever an attack. Plus community engagement has a lot of follow-on benefits for the way your company makes use of open source. This talk covers how to keep surprises to a minimum by engaging with your upstream communities. We'll look at several ways to gracefully go from "who the heck is in charge of that code" to being an open source insider that always knows what’s going on with your upstream partners. We'll also look at how to identify red flags at projects that you may not want to rely on.
Speakers
avatar for Deb Nicholson

Deb Nicholson

Executive Director, Python Software Foundation
Deb Nicholson is an open source software policy expert and a passionate community advocate. She is the Executive Director at the Python Software Foundation which serves as the non-profit steward of the Python programming language. She serves on the Board of Directors for the Spritely... Read More →
Wednesday September 18, 2024 11:55 - 12:35 CEST
Room 2.15 (Level 2)

14:00 CEST

Back to Security Basics: Evaluating, Consuming, and Contributing Open Source Software - Katherine Druckman, Intel
Wednesday September 18, 2024 14:00 - 14:40 CEST
We won! Open source software is everywhere... so now what? Shifting left starts at the beginning – ensuring the security of open source software requires careful evaluation, use, and contribution. This talk will cover some important challenges in securely consuming open source software. Attendees will learn to evaluate projects based on active maintenance, patch cycles, and vulnerability management. We will explore the role of project documentation, code contribution expectations, and community involvement in project maturity and code quality, as well as tools and community guidance. Walk away with the beginnings of a practical framework and checklist that you can mold to your own needs.
Speakers
avatar for Katherine Druckman

Katherine Druckman

Open Source Security Evangelist, Intel Corporation
Katherine Druckman is an Open Source Evangelist at Intel where she enjoys sharing her passion for a variety of open source topics. She is a long-time open source advocate, developer, and podcaster, and is currently the host of Open at Intel and co-host of the FLOSS Weekly and Reality... Read More →
Wednesday September 18, 2024 14:00 - 14:40 CEST
Room 2.15 (Level 2)

15:10 CEST

Extract Dependency Data on Scale with Renovate - Sebastian Poxhofer, N26
Wednesday September 18, 2024 15:10 - 15:50 CEST
As modern platforms integrate an increasing array of tools, so too grows the complexity of software dependencies within your codebase. While mainstream dependencies like Docker images, Terraform and NPM packages are well-covered by existing solutions, what about the myriad obscure or custom tooling, perhaps even manually installed binaries lurking in your Dockerfiles? In this session, we'll unveil an Open Source solution designed to systematically extract data from diverse toolsets. Learn how to effectively catalog, track, and maintain these dependencies, eliminating blind spots and ensuring robustness in your development workflow.
Speakers
avatar for Sebastian Poxhofer

Sebastian Poxhofer

Senior SRE, N26
Sebastian Poxhofer is a seasoned Open Source maintainer and boasts a rich portfolio of projects including Renovate, TargetAllocator of the OpenTelemetry Operator, and more. With a that experience, he spearheads the development of Internal Developer Platforms in his daily endeavor... Read More →
Wednesday September 18, 2024 15:10 - 15:50 CEST
Room 2.15 (Level 2)
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Level
  • Presentation Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -