Loading…
Open Source Summit + Embedded Linux Conference North America...
May 18-20, 2026
Minneapolis, MN
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central DaylightTime (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Venue: 200G (Level Two) clear filter
arrow_back View All Dates
Monday, May 18
 

11:20am CDT

The Exploit of Trust: Securing the Open Source Supply Chain - Kadi McKean, ReversingLabs
Monday May 18, 2026 11:20am - 12:00pm CDT
In 2025, the open source supply chain faced a record-breaking escalation in targeted attacks. This talk breaks down the latest research on how attackers exploit the "trust gap" in maintainer workflows, package repositories, and automated publishing pipelines.

Moving beyond the headlines, this session examines the abuse of repository-native features and the rise of dependency compromises. Participants will walk away with a clear understanding of the evolving threat landscape and the defensive strategies—like reproducible builds and continuous validation—essential for modern software resilience. Join us to learn how to maintain the velocity of open source development while building a foundation of verified trust.
Speakers
avatar for Kadi McKean

Kadi McKean

OSS Community Manager, ReversingLabs
Kadi is passionate about the DevOps / DevSecOps community since her days of working with COBOL development and Mainframe solutions. At ReversingLabs she collaborates with developers and security researchers to help entities prioritize their open source risk, reduce technical debt... Read More →
Monday May 18, 2026 11:20am - 12:00pm CDT
200G (Level Two)
  Packages + Images + Containers
  • Audience Experience Level Any

1:30pm CDT

One Signature To Rule Them All: Portable Supply Chain Verification With Zarf - Brandt Keller, Defense Unicorns
Monday May 18, 2026 1:30pm - 2:10pm CDT
Signed software creates assurances around the integrity and authenticity of how it was produced and by whom. But signing alone is not inherently valuable. The ability to verify the signature in a meaningful way elevates the process to complete the trust cycle.

Blend this idea with many disparate signing mechanisms, add the many layers of exchange as software changes hands and where the software ultimately needs to resolve verification, combine it with many different types of artifacts, and you end up with a complex web of requirements that can be difficult to maintain.

Zarf, an OpenSSF Sandbox project, takes a different approach. Rather than requiring each artifact to be independently verified against external infrastructure, Zarf consolidates artifacts into a declarative package that is pre-verified at creation time. A single signature covers the entire package. The trusted root is embedded in the CLI and the package contains the signature, enabling meaningful verification anywhere, including entirely airgapped environments, with no external connectivity or additional tooling required.
Speakers
avatar for Brandt Keller

Brandt Keller

Staff Software Engineer, Defense Unicorns
Brandt is a Staff Software Engineer with a passion for Open Source. He serves as a Maintainer and Technical Lead for the CNCF Security & Compliance Technical Advisory Group, a Cloud Native Ambassador, and a project maintainer within the OpenSSF. He has lead and contributed to multiple... Read More →
Monday May 18, 2026 1:30pm - 2:10pm CDT
200G (Level Two)
  Packages + Images + Containers
  • Audience Experience Level Any

2:25pm CDT

Lightning Talk: Alcoholless: Lightweight Security Sandbox for Homebrew, AI Agents, Etc. - Akihiro Suda, NTT
Monday May 18, 2026 2:25pm - 2:35pm CDT
This presentation introduces "Alcoholless" Homebrew, which protects macOS hosts from potential malicious Homebrew packages by running Homebrew with a separate user account. A command running with this tool is only allowed to read and write its current directory.

While Alcoholless puts focus on Homebrew, it is also applicable to other package managers such as `pip install`, `npm install`, and `go install`. Aside from package management, it is even useful for running AI coding agents that may potentially execute harmful commands.

Alcoholless is also an attempt to reexamine the necessity of Linux-style containers that emerged in this century. It just utilizes 1990s' commands (`su`, `sudo`, `rsync`) and the macOS equivalent of `useradd` to implement container-like environments, without extending the XNU kernel to support Linux-style container syscalls.

Repository: https://github.com/AkihiroSuda/alcless
Speakers
avatar for Akihiro Suda

Akihiro Suda

Distinguished Software Engineer, NTT
Akihiro Suda is a software engineer at NTT Corporation. He has been a maintainer of Moby (dockerd), BuildKit, containerd, runc, etc. He is also a founder of nerdctl and Lima (CNCF project).
Monday May 18, 2026 2:25pm - 2:35pm CDT
200G (Level Two)
  Packages + Images + Containers

2:55pm CDT

Lightning Talk: Artifacts That Explain Themselves: Build Metadata in Practice - Socheat Sou & Prajakta Kashalkar-Joshi, IBM
Monday May 18, 2026 2:55pm - 3:05pm CDT
It's common practice to include the Git commit hash in a container image label to serve as a reference, but are you using container labels (and artifact metadata) to their full potential? By embedding metadata into your artifacts you expand your GitOps capabilities. Implement a simple build-cache-like mechanism when building your artifacts, generate robust changelogs across your multi-repo product, or provide better transparency to your security team for their audits and reports. It's even possible to perform Git Bisect-like problem determination between built images. While this talk will explore real-world examples using container images as portable sources of truth, these concepts can be applied anywhere it's possible to add additional metadata to built artifacts.
Speakers
avatar for Socheat Sou

Socheat Sou

Senior Software Engineer, IBM
Socheat has 20+ years of experience at IBM across test, development, and DevOps teams. As a DevOps lead, has led the redesign of CI/CD pipelines, implemented automation tools, and improved release management processes, significantly increasing efficiency and reliability. Socheat is... Read More →
avatar for Prajakta Kashalkar-Joshi

Prajakta Kashalkar-Joshi

Senior technical Staff Member, IBM
Prajakta is a DevSecOps Architect at IBM with 20+ years of experience. A DevOps practitioner since 2010, she leads secure CI/CD pipeline development and mentors aspiring DevSecOps professionals. Passionate about advancing women in tech, she supports various inclusion initiatives... Read More →
Monday May 18, 2026 2:55pm - 3:05pm CDT
200G (Level Two)
  Packages + Images + Containers
  • Audience Experience Level Any

3:35pm CDT

StageX: Rebuilding Trust Through Multi-Signed, Full-Source Bootstrapped, and Reproducible Builds - Danny Grove, Manifest Cyber & Lance Vick, Distrust
Monday May 18, 2026 3:35pm - 4:15pm CDT
Most Linux distributions trust individual maintainers with complete package control, creating critical supply chain vulnerabilities. StageX rebuilds this trust model from scratch with a radically different approach: no single person or computer can compromise the system.
StageX requires fully bit-for-bit reproducible builds verified and signed by multiple independent parties before release. Built from 181 bytes of machine code, StageX bootstraps modern toolchains that can be used in container-native and static contexts.
This talk demonstrates StageX's approach to full-source bootstrapping, bit-for-bit reproducibility and multi-party verification; contrasts it with other reproducible build efforts like NixOS/Guix, and shows how its container-native design provides practical security guarantees. You'll learn how to implement these approaches in your own infrastructure to build software from toolchain to deployment.
Speakers
LV

Lance Vick

Security Engineer, Distrust

avatar for Danny Grove

Danny Grove

Lead Infrastructure Engineer, Manifest Cyber
Software and Infrastructure Engineer with 16 years of experience across the web stack. Co-Founder of Hashbang, a decentralized hackerspace. Owner at DR Grove Software LLC and Lead Infrastructure Engineer at Manifest Cyber. Cyborg. Specializes in containerization, building other peoples... Read More →
Monday May 18, 2026 3:35pm - 4:15pm CDT
200G (Level Two)

4:30pm CDT

Image Composer Tool: Declarative Multi-Distro Linux Image Builds From Packages - Mats Agerstam & Alpesh Rodage, Intel Corporation
Monday May 18, 2026 4:30pm - 5:10pm CDT
Building custom Linux images for edge deployments requires distribution-specific toolchains, manual dependency resolution, and bespoke scripting; resulting in fragile, hard-to-reproduce pipelines.

Image Composer Tool (ICT) is an open-source tool that composes bootable Linux images from pre-built packages using declarative YAML templates. It supports Azure Linux, Ubuntu, Wind River eLxr, and Edge Microvisor Toolkit through a single workflow, with dependency resolution across RPM and DEB ecosystems, GPG signature verification, and deterministic builds for CI/CD.

This session covers:

Package management abstraction across RPM and DEB via a unified interface

Reproducible, template-driven builds producing identical outputs from identical inputs

Supply chain security: GPG verification, TLS-secured fetches, minimal attack surface

Extensible provider architecture enabling contributors to add new distributions

Live demo: composing a bootable image from a YAML template in minutes

Attendees will learn how declarative image composition simplifies multi-distribution package management and produces reproducible, secure OS images
Speakers
avatar for Mats Agerstam

Mats Agerstam

Senior Principal Engineer, Intel Corporation
Mats Agerstam is a Senior Principal Engineer at Intel, leading architecture for the Open Edge Platform, Edge Microvisor Toolkit, and OS Image Composer to simplify AI and edge‑native workload deployment. With deep experience in edge computing, device lifecycle management, and platform... Read More →
avatar for Alpesh Rodage

Alpesh Rodage

Cloud Software Architect, Intel Corporation
Alpesh Rodage is a Cloud Software Architect at Intel with 20+ years in platform engineering and distributed systems. He architects and leads development of the OS Image Composer, an open-source tool for declarative, multi-distribution Linux image builds. Previously, he designed multi-cluster... Read More →
Monday May 18, 2026 4:30pm - 5:10pm CDT
200G (Level Two)

5:25pm CDT

Verified Debian Packaging at Scale - Frederick Lawler, Cloudflare
Monday May 18, 2026 5:25pm - 6:05pm CDT
Cloudflare’s global network relies on Debian Linux machines across 330+ cities. To enhance production security we wanted to ensure that our servers can only run authorized software. For this we leverage Linux Kernel's IMA-Measurement to validate binary signatures before execution. Our system encompasses first-party software, Docker containers, and open-source Debian packages.

This talk illustrates how we successfully injected digital signatures into every Debian package installed on our fleet. This involved deep dives into the Linux Kernel, modifying dpkg, and building a mirroring system that could sign upstream repositories. Learn about our journey enhancing software integrity on a massive scale. This session is ideal for those interested in Linux security, package management, and Internet-scale system administration.
Speakers
avatar for Frederick Lawler

Frederick Lawler

Systems Engineer, Cloudflare
Fred is a backend web developer turned kernel developer. He previously focused on the PCIe subsystem since 2018 as a hobbyist. Now he works for Cloudflare on the Linux team with a focus on securing systems and production reliability.
Monday May 18, 2026 5:25pm - 6:05pm CDT
200G (Level Two)
  Packages + Images + Containers
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -