Loading…
Open Source Summit + Embedded Linux Conference North America...
May 18-20, 2026
Minneapolis, MN
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central DaylightTime (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Venue: 200G (Level Two) clear filter
arrow_back View All Dates
Tuesday, May 19
 

11:00am CDT

Trusted Publishing: Eliminating Credentials From Your Release Workflow - Mike Fiedler, Python Software
Tuesday May 19, 2026 11:00am - 11:40am CDT
In February 2024, about 10% of PyPI uploads used Trusted Publishers. By October 2025, that number exceeded 25%, a massive shift toward eliminating long-lived credentials. For maintainers still using stored API tokens, this talk demonstrates why and how to modernize.

Trusted Publishing uses OpenID Connect (OIDC) to generate short-lived, automatically-scoped tokens from CI/CD environments. No passwords. No API tokens to rotate. No secrets stored in repositories.

This talk walks through setting up Trusted Publishers for GitHub Actions (as an example, but others are available), explains the security model in accessible terms, and shares case studies, including how Sigstore integration enabled forensic investigation of the 2024 Ultralytics compromise.

Attendees will learn the step-by-step setup process, common pitfalls and troubleshooting, and migration strategies for maintainers with many packages. The session also covers why token removal is critical when Trusted Publishing in place, and when restricted API tokens remain the appropriate fallback. Whether maintaining one package or a hundred, attendees will leave with everything needed to adopt credential-free publishing.
Speakers
avatar for Mike Fiedler

Mike Fiedler

PyPI Safety & Security Engineer, Python Software Foundation
Mike’s been in the engineering game for 30+ years, leading teams at Datadog, MongoDB, LeafLink, Warby Parker, and Capital One. He’s a big believer in learning from every peer and helping others navigate tech’s complexities. An AWS Hero and Awesome Community Chef, Mike loves... Read More →
Tuesday May 19, 2026 11:00am - 11:40am CDT
200G (Level Two)
  Packages + Images + Containers

11:55am CDT

Package Testing Across Distributions and Architectures at Scale: A Molecule and QEMU Approach - Yash Panchal, Percona
Tuesday May 19, 2026 11:55am - 12:35pm CDT
This session will demonstrate a scalable approach to testing Linux packages across multiple distributions and architectures using Molecule and QEMU/KVM.

Attendees will learn how to build automated testing pipelines that validate linux packages on diverse platforms including x86_64, ARM64, RHEL, Ubuntu, and Debian.

We'll cover practical implementation of Molecule test scenarios, integration with Jenkins CI/CD pipelines, efficient use of QEMU/KVM for multi-architecture testing, and image pre-baking strategies to significantly reduce test execution time.

The talk includes real-world examples from database and toolkit package testing at Percona, demonstration of creating optimized base images, comparisons with cloud instances, Docker and Firecracker alternatives, and best practices for maintaining test infrastructure.

Key takeaways: Setting up Molecule package testing frameworks, managing QEMU instances, implementing image pre-baking workflows, handling cross-architecture testing challenges, and achieving speed and cost savings in testing linux packages.
Speakers
avatar for Yash Panchal

Yash Panchal

SDET III, Percona
Yash Panchal is an SDET III at Percona, where he specializes in automating and testing database and toolkit packages across supported linux distributions and architectures.

A seasoned open-source speaker, Yash presented a session on package testing with Molecule and Jenkins at... Read More →
Tuesday May 19, 2026 11:55am - 12:35pm CDT
200G (Level Two)

2:10pm CDT

Package Managers Metadata and Cross Ecosystem Projects in the Era of SBOMs - Damián Vicino, Datadog
Tuesday May 19, 2026 2:10pm - 2:50pm CDT
Package managers do more than resolve dependencies—they shape how software and its metadata are distributed across the ecosystem. While they simplify development, they also introduce large, fast-moving transitive dependency trees that are rarely inspected in depth.
Despite evolving independently, most package managers share a common model: distributing artifacts alongside metadata. Yet metadata formats, completeness, and quality vary widely across ecosystems, creating challenges for security analysis, compliance, and supply chain risk management—especially in today’s hybrid, multi-language environments.
This talk examines how package metadata is increasingly used beyond builds, powering vulnerability management, license compliance, and Software Bill of Materials (SBOM) generation through standards such as SPDX and CycloneDX.
Based on the results from the first year of work from the CHAOSS Package Metadata Working Group—an analysis of more than 40 package managers—we’ll share emerging best practices, gaps we’ve identified, and recommendations for both new and existing ecosystems to improve metadata quality, interoperability, and transparency.
Speakers
avatar for Damián Vicino

Damián Vicino

Senior Open Source Specialist, Datadog
Damian Vicino is a Senior Open Source Specialist at Datadog’s OSPO and an Adjunct Research Professor at Carleton University. He began contributing to open source in the early 2000s, leading a local BSD user group and collaborating with a team on five BSDday Argentina events. He... Read More →
Tuesday May 19, 2026 2:10pm - 2:50pm CDT
200G (Level Two)
  Packages + Images + Containers
  • Audience Experience Level Any

3:05pm CDT

What Are You Willing To Digest? Multi Arch Container Image Security and Best Practice - Evans Yeboah Jr., VideoAmp
Tuesday May 19, 2026 3:05pm - 3:45pm CDT
Deploying apps in containers is easier than ever, but securing the image these containers come from is a dynamic security problem that on its surface has no single best answer. So when it comes to what risk you may face and what risk you are willing to accept, one of the questions that may come up is if snowflake-y multi architecture risks are something you are willing to digest?

With multi arch images, based on the system it is deployed to, its vulnerabilities profile may look different than any of the other supported systems. So in this talk I will be demonstrating a security tool agnostic way to handle identifying and remediating these threats. I will go through how anyone (at any level of security experience) can automate container security across pipelines without slowing down development. Attendees will walk away with a new understanding of the importance of minimizing exposure to these risks, as well as a clearer understanding of the layered setup of multi arch container images (index manifest, platform manifest, and image manifest). And without a doubt, walk away with container image security and not unmanaged risk, something they are willing to digest.
Speakers
avatar for Evans Yeboah Jr.

Evans Yeboah Jr.

Senior Security Engineer, VideoAmp
Cyber security and AI security enthusiasts who likes to build stuff but also make sure it's secure. Engineer by day and baker by night, honing both crafts by failing forward every day.
Tuesday May 19, 2026 3:05pm - 3:45pm CDT
200G (Level Two)
  Packages + Images + Containers

4:20pm CDT

NixOS for Deterministic Distributed-System Benchmarking - B. Cameron Gain, ReveCom
Tuesday May 19, 2026 4:20pm - 5:00pm CDT
Reproducibility remains one of the largest challenges in benchmarking distributed systems, especially when hardware, kernel-level parameters and dependency versions vary between tests. This talk presents a NixOS-based approach for constructing deterministic, portable benchmark environments for large-scale data infrastructure. We show how Nix’s declarative system configuration, content-addressed builds and reproducible packaging model allow engineers to isolate performance variables.

We look at how Nix offers a much more reproducible environment when producing different applications for testing. While Docker containers isolate user-space dependencies, they remain tied to the host kernel's version and configuration.

Using Apache Cassandra as the primary case study, the talk demonstrates how NixOS can define and reproduce complete cluster environments. Attendees will learn practical patterns for packaging workloads, pinning dependencies, and generating ephemeral benchmark nodes.

The session concludes with a live demo of how we can initiate benchmark tests on Nix and then kill the entire infrastructure in just a few seconds.


Speakers
avatar for B. Cameron Gain

B. Cameron Gain

Analyst, ReveCom
B. Cameron Gain is co-founder and publisher of ReveCom Media.
Tuesday May 19, 2026 4:20pm - 5:00pm CDT
200G (Level Two)
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -