Loading…
Attending this event?
September 16-18, 2024
Vienna, Austria
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central European Summer Time (UTC/GMT +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

SupplyChainSecurityCon clear filter
Tuesday, September 17
 

11:00 CEST

Panel Discussion: Improving the Software Supply Chain Security - Arnaud Le Hors, IBM; Isaac Hepworth, Google; Michael Lieberman, Kusari; and Marina Moore, Independent
Tuesday September 17, 2024 11:00 - 11:40 CEST
OpenSSF and other organizations such as CNCF have been developing new technologies aiming at improving the security posture of open source and the software supply chain. This panel will give attendees a chance to hear from the very people involved in the development of some of these technologies and learn what's behind names like SLSA, S2C2F, and GUAC, the status of these technologies and how they relate to one another.
Speakers
avatar for Michael Lieberman

Michael Lieberman

Co-Founder and CTO, Kusari
Michael Lieberman is co-founder and CTO of Kusari where he helps build transparency and security in the software supply chain. Michael is an active member of the open-source community, co-creating the GUAC and FRSCA projects and co-leading the CNCF’s Secure Software Factory Reference... Read More →
avatar for Arnaud Le Hors

Arnaud Le Hors

Senior Technical Staff Member Open Technologies, IBM
Arnaud Le Hors is Senior Technical Staff Member of Open Technologies at IBM, primarily focusing on Open Source security. He has been working on standards and open source for over 25 years. Arnaud was editor of several key web specifications including HTML and DOM and was a pioneer... Read More →
avatar for Marina Moore

Marina Moore

Researcher, Independent
Marina Moore is a PhD candidate at NYU Tandon’s Secure Systems Lab researching secure software updates and software supply chain security. She is a maintainer of The Update Framework (TUF), a CNCF graduated project, as well as in-toto, an incubating project. She contributed to the... Read More →
avatar for Isaac Hepworth

Isaac Hepworth

Group Product Manager, Google
Isaac is a Google product manager working on software supply chain integrity within Google’s core infrastructure team, focusing on open source. In this role his work has supported Google’s contributions to OpenSSF's Sigstore, SLSA, and most recently GUAC. Over the last couple... Read More →
Tuesday September 17, 2024 11:00 - 11:40 CEST
Room 0.96-0.97 (Level 0)

11:55 CEST

Policing Open-Source Projects at Scale - Thomas Neidhart, Eclipse Foundation
Tuesday September 17, 2024 11:55 - 12:35 CEST
Large open-source foundations like the Eclipse Foundation are faced with the challenge of maintaining thousands of repositories for the numerous projects and monitoring that these repositories adhere to certain policies and security guidelines to provide an open, transparent and secure environment for the development of open-source software. We would like to present our approach to tackle these challenges: a system where our projects as hosted on GitHub have their configuration stored as code in a repository itself, and project members can request changes to this configuration by opening a pull request, and once approved, changes get applied automatically. With this approach it is possible to make the current infrastructure of a project transparent to everyone involved, highlight items that should be addressed to adhere to certain policies and empower teams to improve and secure their repositories more easily. In this talk we would also like to outline what we have learned while rolling out this service to projects at the Eclipse Foundation and how such an approach can help to increase collaboration in your community as members are able to learn from each other.
Speakers
avatar for Thomas Neidhart

Thomas Neidhart

Security Engineer, Eclipse Foundation
Passionate open source developer, focused on helping open-source projects to be more productive and secure.
Tuesday September 17, 2024 11:55 - 12:35 CEST
Room 0.96-0.97 (Level 0)

14:00 CEST

Planning for Retirement: How Can We Prepare for Software’s End-of-Life/End-of-Support Date? - Victoria Ontiveros, CISA & Justin Murphy, DHS/CISA
Tuesday September 17, 2024 14:00 - 14:40 CEST
The ambiguity surrounding terminology and general uncertainty amplifies the end-of-life/end-of-support problem: What is end-of-life? How is end-of-life different from end-of-support? How does this affect supply chain and operational security? This presentation will begin with an overview of the EOL/EOS problem and suggest definitions for key terms to the discussion. Creating shared terminology can support the community in facilitating discussions around EOL/EOS and generating solutions. This presentation will map the EOL/EOS problem to other ongoing discussions including software naming and versioning, acknowledging that this is not a new problem and it is unlikely there is one singular solution. The presentation will also include discussion of the potential role of existing software transparency and supply chain security efforts, such as SBOM, VEX, and CSAF, may play in managing EOL/EOS. We will highlight the OpenEoX efforts from the OASIS community seeking to develop an open source, standardized method to ascertain the EOL/EOS status of products, as well as other ongoing policy efforts. The presentation will close with time for feedback on the presentation and discussion.
Speakers
avatar for Justin Murphy

Justin Murphy

Vulnerability Analyst, DHS/CISA
Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s... Read More →
avatar for Victoria Ontiveros

Victoria Ontiveros

Cybersecurity Specialist, CISA
Victoria Ontiveros joined the Cybersecurity and Infrastructure Security Agency (CISA) in June 2023 as a cybersecurity specialist. At CISA, she supports the agency's software bill of materials (SBOM) work, collaborating with partners across the software ecosystem, U.S. government... Read More →
Tuesday September 17, 2024 14:00 - 14:40 CEST
Room 0.96-0.97 (Level 0)

14:55 CEST

VSCorode: Inside Your IDE, Inside Your Git Repository - Kevin Ward & Fabian Kammel, ControlPlane
Tuesday September 17, 2024 14:55 - 15:35 CEST
For several years now we’ve heard the mantra of shifting left to move security as early as possible in the development process. The aim is to enable developers to understand and produce secure code right away. The primary method to support developers is to enhance their IDE with extensions which can identify security issues, highlight insecure code practices and handle integration with external services. VSCode is one of the most popular IDEs with a flourishing community of extensions for data manipulation, theming, programmatic language features and additional debugging functionality. There is a great deal of trust placed in these extensions so what would happen if an extension turned against you? This talk explores the supply chain risks associated with VSCode extensions, what is required to get an extension included in the marketplace and how simply we hand over control to an unknown third party. We will demonstrate what an adversary can achieve with a malicious extension and how it represents a future red team target from enumeration, persistence and execution.Lastly we’ll offer advice on how to prevent common attack paths.
Speakers
avatar for Kevin Ward

Kevin Ward

Principal Consultant, ControlPlane
Kevin is an Principal Consultant with over 10 years of experience designing, building and testing secure solutions for Government, Defence and Finance sectors. In his own time, Kevin enjoys hacking and hardening systems to discover the balance between security and usability. He co-authored... Read More →
avatar for Fabian Kammel

Fabian Kammel

Senior Security Consultant, ControlPlane
Fabian Kammel is a Senior Security Consultant at ControlPlane, where he helps to make the (cloud-native) world a safer place. His goal is to bring hardware security and cloud-native security closer together, as well as, improving the developer experience in the security space. He... Read More →
Tuesday September 17, 2024 14:55 - 15:35 CEST
Room 0.96-0.97 (Level 0)

16:00 CEST

"Here Is a Clean Section of the Beach" - Proactively Auditing Open Source Dependencies and Letting E - Munawar Hafiz, OpenRefactory & Michael Winser, Alpha-Omega
Tuesday September 17, 2024 16:00 - 16:40 CEST
Open source dependencies pose the most serious threat for all software. Software Composition Analysis (SCA) tools can help understand the risk profile using data collected about known vulnerabilities. But what about the unknown ones? The Alpha-Omega project, sponsored by Amazon, Google and Microsoft, has been challenged with the tasks of scouring the most popular Open Source libraries in order to “clean the beach” to make it safe for everyone. But the beach is huge and how can this project be performed at scale? In this talk, Michael Winser, Alpha-Omega co-founder, and Dr. Munawar Hafiz, CEO of OpenRefactory, will discuss the progress that Alpha-Omega has made in scanning and repairing thousands of Open Source libraries. They will describe the scaling challenges, the data handling and storage challenges and how the information is made available to the end users.
Speakers
avatar for Munawar Hafiz

Munawar Hafiz

CEO, OpenRefactory
Munawar Hafiz is the founder and head of innovations of OpenRefactory, Inc., an application security company that intends to improve the way developers write secure, reliable and compliant code. Munawar had a body of work on automated bug fixing in academia which lays the foundation... Read More →
avatar for Michael Winser

Michael Winser

Co-founder, Alpha-Omega
Michael is a 40 year veteran in the software industry, with over 25 of those years at Google and Microsoft. He co-founded Alpha-Omega while at Google. Michael is an industry expert in software supply chain security, software development, and developer ecosystems. In addition to Alpha-Omega... Read More →
Tuesday September 17, 2024 16:00 - 16:40 CEST
Room 0.96-0.97 (Level 0)
 
Wednesday, September 18
 

11:00 CEST

Enhancing Artifact Security with GitHub’s Build Provenance and Minder - Fredrik Skogman, GitHub & Radoslav Dimitrov, Stacklok
Wednesday September 18, 2024 11:00 - 11:40 CEST
In the evolving landscape of software development, ensuring the integrity of build artifacts like container images is crucial. In this talk, we'll demonstrate how to use GitHub's Build Provenance API to generate SLSA attestations and create robust policies for your artifacts, verifying their origin and authenticity. We'll examine the contents and significance of these attestations and discuss how to integrate them into your CI/CD pipelines. Additionally, we'll explore using Minder to monitor and enforce these policies across your repositories, ensuring these attestation practices do not degrade over time. We’ll also show how combining these tools can safeguard even in the event of someone else gaining access and pushing a malicious image to your container registry. By the end of this session, you'll have a good understanding of how open source tools like Sigstore, in-toto, SLSA, TUF, and Minder can collectively strengthen the security of the software supply chain. You'll gain practical insights into setting up artifact attestations with GitHub's API and establishing tailored policies with Minder to protect your development processes against vulnerabilities.
Speakers
avatar for Radoslav Dimitrov

Radoslav Dimitrov

Senior Software Engineer, Stacklok
Radoslav Dimitrov is a Senior Software Engineer at Stacklok. He's a maintainer of go-tuf, RSTUF and Minder and is contributing to several other software supply chain projects. His interests include mountain biking, cats, coffees and everything that relates to DIY.
avatar for Fredrik Skogman

Fredrik Skogman

Staff Engineer, GitHub
Fredrik is a Staff Engineer on the Package Security Engineering team at GitHub, where he focuses on software supply chain security. At GitHub he provides technical leadership for standards and tools in the supply chain security space, most recently co-authoring the published npm RFC... Read More →
Wednesday September 18, 2024 11:00 - 11:40 CEST
Room 0.96-0.97 (Level 0)

11:55 CEST

Measuring Security Risk: Community Engagement Is the Best Mitigation - Deb Nicholson, Python Software Foundation
Wednesday September 18, 2024 11:55 - 12:35 CEST
When considering open source software that you include in your products, engaging with your upstream is a more robust and resilient way to gauge your security risks than relying on outsourcing your trust modeling to metrics and GitHub stars. Becoming a partner to your upstream community helps you build more secure software and create the relationships you'll need if there's ever an attack. Plus community engagement has a lot of follow-on benefits for the way your company makes use of open source. This talk covers how to keep surprises to a minimum by engaging with your upstream communities. We'll look at several ways to gracefully go from "who the heck is in charge of that code" to being an open source insider that always knows what’s going on with your upstream partners. We'll also look at how to identify red flags at projects that you may not want to rely on.
Speakers
avatar for Deb Nicholson

Deb Nicholson

Executive Director, Python Software Foundation
Deb Nicholson is an open source software policy expert and a passionate community advocate. She is the Executive Director at the Python Software Foundation which serves as the non-profit steward of the Python programming language. She serves on the Board of Directors for the Spritely... Read More →
Wednesday September 18, 2024 11:55 - 12:35 CEST
Room 0.96-0.97 (Level 0)

14:00 CEST

Back to Security Basics: Evaluating, Consuming, and Contributing Open Source Software - Katherine Druckman, Intel
Wednesday September 18, 2024 14:00 - 14:40 CEST
We won! Open source software is everywhere... so now what? Shifting left starts at the beginning – ensuring the security of open source software requires careful evaluation, use, and contribution. This talk will cover some important challenges in securely consuming open source software. Attendees will learn to evaluate projects based on active maintenance, patch cycles, and vulnerability management. We will explore the role of project documentation, code contribution expectations, and community involvement in project maturity and code quality, as well as tools and community guidance. Walk away with the beginnings of a practical framework and checklist that you can mold to your own needs.
Speakers
avatar for Katherine Druckman

Katherine Druckman

Open Source Security Evangelist, Intel
Katherine Druckman is an Open Source Evangelist at Intel where she enjoys sharing her passion for a variety of open source topics. She is a long-time open source advocate, developer, and podcaster, and is currently the host of Open at Intel and co-host of the FLOSS Weekly and Reality... Read More →
Wednesday September 18, 2024 14:00 - 14:40 CEST
Room 0.96-0.97 (Level 0)

15:10 CEST

The Missing Post Mortem - Tobie Langel, UnlockOpen
Wednesday September 18, 2024 15:10 - 15:50 CEST
The first half of 2024 saw an entirely new category of threat against open source, one that rocked its trust-based system at its core: social engineering takeover attempt of critical open source projects. These attacks uncovered a systemic gap in open source security management. Up until now, the open source community wasn’t thought of as a potential cyber attack target. But when critical open source projects become stepping stones for industrial espionage, ransomware attacks, or cyberwarfare, maintainers need to adopt comparable security practices to those found in target organizations. This creates a unique set of challenges for open source because of its highly distributed nature and volunteer-based model. In this talk we'll do a post-mortem of the social engineering takeover attempt at the OpenJS Foundation. Without revealing confidential information, we'll still be able to outline critical industry gaps uncovered during this attack and suggest ways to meaningfully improving security at scale while preserving the ethos, culture, and diversity of communities that characterize open source.
Speakers
avatar for Tobie Langel

Tobie Langel

Principal, UnlockOpen
Tobie Langel is a world-leading expert on open source and standardization. He advises some of the biggest names in tech (Google, Microsoft, Mozilla, Intel, Cisco), promising startups (Airtable, Postman, GitLab), industry organizations (OpenJS Foundation, OASIS Open, W3C) and nonprofits... Read More →
Wednesday September 18, 2024 15:10 - 15:50 CEST
Room 0.96-0.97 (Level 0)

16:05 CEST

Extract Dependency Data on Scale with Renovate - Sebastian Poxhofer, N26
Wednesday September 18, 2024 16:05 - 16:45 CEST
As modern platforms integrate an increasing array of tools, so too grows the complexity of software dependencies within your codebase. While mainstream dependencies like Docker images, Terraform and NPM packages are well-covered by existing solutions, what about the myriad obscure or custom tooling, perhaps even manually installed binaries lurking in your Dockerfiles? In this session, we'll unveil an Open Source solution designed to systematically extract data from diverse toolsets. Learn how to effectively catalog, track, and maintain these dependencies, eliminating blind spots and ensuring robustness in your development workflow.
Speakers
avatar for Sebastian Poxhofer

Sebastian Poxhofer

Senior SRE, N26
Sebastian Poxhofer is a seasoned Open Source maintainer and boasts a rich portfolio of projects including Renovate, TargetAllocator of the OpenTelemetry Operator, and more. With a that experience, he spearheads the development of Internal Developer Platforms in his daily endeavor... Read More →
Wednesday September 18, 2024 16:05 - 16:45 CEST
Room 0.96-0.97 (Level 0)
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.