Loading…
Open Source Summit + Embedded Linux Conference North America...
May 18-20, 2026
Minneapolis, MN
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central DaylightTime (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Venue: 200A (Level Two) clear filter
arrow_back View All Dates
Monday, May 18
 

11:20am CDT

Panel Discussion: OSPOs at Scale: Doing More With Less in 2026 - Ashley Wolf, GitHub; Karolyn Maynard, Comcast; Natali Vlatko, Cisco; Paulette Avolio, Ford; Rashida Toliver, Violane LLC
Monday May 18, 2026 11:20am - 12:00pm CDT
Open Source Program Offices are maturing. What started as license compliance and governance functions have evolved into strategic enablers of security, AI adoption, developer productivity, and ecosystem engagement. At the same time, budgets are tighter and expectations are higher.

In this moderated panel, OSPO leaders from Ford, GEICO, Comcast, Cisco and GitHub will discuss how modern OSPOs are scaling impact. We’ll explore practical approaches to automation, policy design, internal enablement, and cross-functional alignment. We’ll share how OSPOs are using metrics to demonstrate value, navigating AI-era contribution models, and leveraging communities like the TODO Group to accelerate learning.

Attendees will leave with concrete examples of how enterprise OSPOs are evolving beyond compliance, how to prioritize when resources are constrained, and how to build influence across engineering, security, and leadership teams.

Whether you're starting an OSPO or leading a mature one, this session offers candid lessons from practitioners operating at scale.
Speakers
avatar for Ashley Wolf

Ashley Wolf

Director, Open Source, GitHub
Ashley Wolf is the Director of Open Source Programs at GitHub. She runs initiatives and programs to empower developers to be successful with open source. She is also passionate about helping companies participate in the open source community. Prior to joining GitHub, Ashley led the... Read More →
avatar for Karolyn Maynard

Karolyn Maynard

Leader of the Comcast Open Source Program Office and The Comcast Dojo, Comcast
I build systems, I build people. I build trust. I build momentum,

I lead two teams at Comcast focused on engineering enablement and transformation: the Comcast Open Source Program Office, which empowers safe and scalable open source participation, and the Comcast Dojo (NPS: 76), which accelerates developer practices through immersive, outcome-driv... Read More →
avatar for Natali Vlatko

Natali Vlatko

Director of Open Source Software Engineering, Cisco
Natali Vlatko (she/her) is a Director of Open Source Software Engineering at Cisco, specializing in open software, policy, and governance. She is a SIG Docs Co-Chair for Kubernetes and a member of the TODO Group Steering Committee. She plays on the fun computer in her spare time... Read More →
avatar for Paulette Avolio

Paulette Avolio

Open Source Program Office Manager, Ford
I help connect people, policies and products to elevate open source community, compliance and contributions.
avatar for Rashida Toliver

Rashida Toliver

Co-Founder & Security Strategist, Violane LLC
Rashida Toliver is a Security Engineer II at GEICO and Co-Founder of Violane Tech LLC. She builds data-driven vulnerability management systems, leads open-source contribution governance, and mentors emerging engineers. Through Violane Tech, she delivers data management, visualization... Read More →
Monday May 18, 2026 11:20am - 12:00pm CDT
200A (Level Two)
  OSS Enabling & Management

1:30pm CDT

Strategic Approach To Demonstrating the Value of OSS Efforts - Dawn Foster, Independent
Monday May 18, 2026 1:30pm - 2:10pm CDT
We’ve probably all had company leadership question the value of our OSS efforts. It can be difficult to frame the value in ways that resonate with leadership and clearly articulate the organizational benefits gained through continued OSS contributions. Taking a strategic approach that connects the OSS work with the broader goals and objectives of the organization can demonstrate the value of this work so that the organization can continue to allocate resources to the OSPO or other OSS teams.

Using examples from my decades of experience in OSS, this talk will provide details about how to demonstrate value by focusing on how your OSS work helps the organization achieve their strategies and goals. Every organization has unique needs and goals based on what they are trying to achieve, so there is no “one size fits all” way of demonstrating value, but aligning your OSS strategy with your organization’s goals and focusing on the most strategic projects can help show the value of your efforts. This talk will help you reason about how OSS efforts allow your organization to achieve its goals along with framing and communicating that value in ways that resonate with your leadership team.
Speakers
avatar for Dawn Foster

Dawn Foster

Open Source Strategy Consultant, Self-Employed
Dr. Dawn Foster is an OSS strategy consultant. She is also on the board of CHAOSS and OpenUK, and was previously a co-chair of the CNCF Contributor Strategy Technical Advisory Group. She has 20+ years of experience at companies like VMware and Intel with expertise in community, strategy... Read More →
Monday May 18, 2026 1:30pm - 2:10pm CDT
200A (Level Two)

2:25pm CDT

Scaling Your OSPO With Agents and Automation: Lessons From GitHub's Open Source Program - Ashley Wolf, GitHub
Monday May 18, 2026 2:25pm - 3:05pm CDT
As open source adoption grows, the role of the OSPO expands with it. At GitHub, we saw an opportunity to scale our capabilities by automating the repetitive work—like checklists, scans, reports, and audits—that every program office handles.

In this session, I’ll outline how we evaluated AI agents to handle the heavy lifting of data gathering and analysis. We’ll look at practical use cases for automating OSPO activities like review, compliance, reporting, including dependency analysis and license detection, using data from sources like ClearlyDefined and OpenSSF Scorecard.

Join me as we explore the patterns that worked, the surprises we encountered, and how these workflows provide a comprehensive view of project health for OSPOs. You’ll leave with a framework for applying AI, agents, agentic workflows to your own OSPO’s challenges, helping you scale your operations efficiently across the entire open source lifecycle.
Speakers
avatar for Ashley Wolf

Ashley Wolf

Director, Open Source, GitHub
Ashley Wolf is the Director of Open Source Programs at GitHub. She runs initiatives and programs to empower developers to be successful with open source. She is also passionate about helping companies participate in the open source community. Prior to joining GitHub, Ashley led the... Read More →
Monday May 18, 2026 2:25pm - 3:05pm CDT
200A (Level Two)

3:35pm CDT

Taming MCP Server Sprawl: Securing and Scaling the Model Context Protocol in Production - Jeffrey Borek & Olivia Buzek, IBM
Monday May 18, 2026 3:35pm - 4:15pm CDT
As AI agents transition from pilots to production systems, enterprises are rapidly adopting the open source Model Context Protocol (MCP) to connect models with tools, data, and services. But this flexibility introduces a new challenge: MCP server sprawl. Proliferating endpoints, inconsistent trust models, weak identity controls, and unclear governance can quickly create operational and security risk. This session explains what MCP is, why its adoption is accelerating, and where architectural pitfalls emerge at scale. Developers will learn key design principles for secure deployment, including authentication patterns, authorization boundaries, observability, lifecycle management, and policy enforcement. Attendees will leave with a practical mental model for building MCP integrations that remain composable, governable, and production-ready as ecosystems evolve.
Speakers
avatar for Jeffrey Borek

Jeffrey Borek

WW Program Director, Open Technologies, IBM
Working across IBM Research to build a scalable and consistent AI software supply chain security framework, while continuing to lead the consumption compliance Open Source Program Office (OSPO), including policy, execution and guidance. Working with IBM Government & Regulatory Affairs... Read More →
avatar for Olivia Buzek

Olivia Buzek

Senior Staff Developer Advocate for AI, IBM
Olivia is a computational linguist turned AI engineer. Her career has focused on data, machine learning, and AI. She subscribes to neither AI hype nor AI doomerism, believing that human creativity and AI can coexist, and that builders of AI applications have a responsibility to their... Read More →
Monday May 18, 2026 3:35pm - 4:15pm CDT
200A (Level Two)

4:30pm CDT

Lazy Rivers and Open Source Security: Learn About the OpenSSF With Angelah and Stacey - Angelah Liu & Stacey Potter, Linux Foundation
Monday May 18, 2026 4:30pm - 5:10pm CDT
Some people claim that open source and cybersecurity are two things that don't mix. Come join this informative session to learn how the truth is very much the opposite!

Established in 2020, the OpenSSF is the security subject matter experts for the Linux Foundation. While some might claim that security is a Dark Art, hop onto our lazy river as we show you about all the amazing initiatives our community has to offer open source developers and downstream OSS consumers! Don't forget your towel and some sunscreen, and be careful if you sit in the splash-zone... you MAY get wet! HONK!
Speakers
avatar for Angelah Liu

Angelah Liu

Associate Manager, Marketing and Communications, Linux Foundation
Angelah serves as the Associate Communications & Marketing Manager at the Linux Foundation, where she supports open source projects' cross-functional marketing initiatives for high-impact open source ecosystems. She drives the marketing efforts for multiple key LF projects, including... Read More →
avatar for Stacey Potter

Stacey Potter

Community Manager, OpenSSF
Stacey brings extensive experience in open source community building, marketing, and event coordination. With a background spanning projects like Minder, Flux and Flagger, OpenFeature, and Keptn, she has played a key role in fostering engagement and driving adoption across cloud-native... Read More →
Monday May 18, 2026 4:30pm - 5:10pm CDT
200A (Level Two)

5:25pm CDT

From Compliance To Code: The Cyber Resilience Act, SBOMs, DevTeams and YOU! - Marcus Ross, Hamburg Port Authority AöR & Peter Dickten, dcs-fuerth Germany
Monday May 18, 2026 5:25pm - 6:05pm CDT
The EU Cyber Resilience Act (CRA) is reshaping how manufacturers and developers must secure their products—but what does it mean for your Developer platforms, DevOps pipelines, and DevTeams? In this session, we’ll share a real-world implementation for SBOMs (Technical Guideline TR-03183 from the Federal Office of Information Security). We demonstrate how to technically address CRA mandates without drowning in compliance overhead.

You will leave with
- Understand the CRA’s impact on your Developers and Management even outside the EU (and why ignoring it isn’t an option).
- See a production-ready workflow for SBOMs, vulnerability management, and compliance automation with OpenSource-Tools (DependencyTrack, CentralCyclone, GitOps).
- Actionable insights on integrating CRA requirements with SBOM handling into your CI/CD pipelines.
- A clear "why this matters" for your org., and lessons from the trenches of securing critical infrastructure with Kubernetes.
- Get a checklist for team adoption - because compliance is a cultural challenge, not just a technical one.
Speakers
avatar for Peter Dickten

Peter Dickten

Peter Dickten, dcs-fuerth Germany

avatar for Marcus Ross

Marcus Ross

CCoE Lead / Kubestronaut, Hamburg Port Authority
The Hamburg Port Authority (HPA) has been operating future-oriented port management from a single source since 2005 and is active wherever efficiency, safety, and cost-effectiveness are required in the Port of Hamburg. Marcus works as a DevOps Plattform Engineer in a team responsible... Read More →
Monday May 18, 2026 5:25pm - 6:05pm CDT
200A (Level Two)
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -