Loading…
Audience: Intermediate clear filter
Tuesday, October 6
 

11:15am CEST

How To Be a Good Citizen Contributor To Open Source in the Age of Regulation - Roman Zhukov, Red Hat & George Kunz, Ericsson
Tuesday October 6, 2026 11:15am - 11:40am CEST
Every Linux Foundation member relies on community-maintained open source, but regulations like the EU CRA now mandate upstream contributions. This "enforced collaboration" has led some companies to shove pull requests and demand immediate response from the community, often lacking awareness of the diverse open source governance and contributing norms.

Co-presented by open source leaders from Red Hat and Ericsson, this session outlines how member organizations can responsibly contribute back to open source while preserving upstream health. It highlights two OpenSSF initiatives. First, a Concise Guide for Upstream Collaboration, developed by the Best Practices WG and aiming to help OSPOs guide employees through security upstream contributions. Second, the deliverables of the Global Cyber Policy WG, including CRA Maintainer Guidance, demonstrating how community developers can establish clear consumption expectations, shielding them from unreasonable compliance pressure.

Attendees will leave with a clear sense for how to shift their open-source strategies from a corporate risk function to a collaborative model that secures their products and helps the broader open-source ecosystem.
Speakers
avatar for Georg Kunz

Georg Kunz

Director Open Source Software, Ericsson
Georg is a director in Ericsson's Open Source Program Office. He is a passionate advocate for open source software and a long term contributor to a wide range of open source projects. He currently serves on the Technical Advisory Council and the Governing Board of the Open Source... Read More →
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product... Read More →
Tuesday October 6, 2026 11:15am - 11:40am CEST
Panorama Hall

12:15pm CEST

Sovereignty Requires Open: Building Europe's Shared Geospatial Commons - Albi Wiedersberg, Overture Maps Foundation
Tuesday October 6, 2026 12:15pm - 12:40pm CEST
European organizations face a strategic challenge between proprietary vendor lock-in and isolated, redundant infrastructure builds. True digital sovereignty isn't achieved through isolation, which forces public and private entities to waste up to 90% of their engineering resources on baseline data preparation. European sovereignty requires open data, shared reference standards, and neutral governance.

Using the Overture Maps Foundation as a primary case study, this session demonstrates how open spatial data and universal entity identifiers function as public utility infrastructure for Europe. We examine how open infrastructure eliminates the data harmonization tax for municipalities and enterprises, enables trustworthy AI grounding, and balances European digital autonomy with global open source collaboration. Attendees will gain actionable frameworks for leveraging federated, open data layers to preserve operational independence while accelerating innovation across the European technology commons.
Speakers
avatar for Albi Wiedersberg

Albi Wiedersberg

Vice President of Product Management, Overture Maps Foundation
Albi Wiedersberg is the Vice President of Product Management at Overture Maps Foundation. With over 15 years of experience in product and technology leadership, he is dedicated to building high-quality, open, and interoperable map and location data as a shared resource for innovation... Read More →
Tuesday October 6, 2026 12:15pm - 12:40pm CEST
Panorama Hall

4:15pm CEST

Open Source Collaboration Across Projects To Build Platforms - Using SCS as Example - Kurt Garloff, S7n Cloud Services GmbH & Felix Kronlage-Dammers, Open Source Business Alliance e.V.
Tuesday October 6, 2026 4:15pm - 4:40pm CEST
Open Source Software (OSS) has been very successful in bringing together contributors, crossing organizational, cultural, regional borders. Clouds combine a lot of technology into cohesive platforms and are thus harder. Big Tech uses a lot of OSS, but ultimately combines it into highly proprietary platforms built to lock-in customers into vendor-specific APIs and service sets. To compete successfully without the vast amount of financial resources, strong collaboration practices and a powerful vision is needed to motivate the broad cross-project work.

Sovereign Cloud Stack (SCS) is a European initiative that creates an open, transparent, and vendor-neutral cloud ecosystem that guarantees sovereignty. SCS is based on certifiable standards, a modular software stack, and practical knowledge transfer. The project is steered by a community project board with standardization and certification overseen by the Forum SCS-Standards.

Standing on the shoulders of giants, it builds on top of many successful open-source components, such as OpenStack and Kubernetes. The certifiable standards assure that workloads can be switched easily between cloud environments that are SCS-compatible.
Speakers
avatar for Kurt Garloff

Kurt Garloff

CEO, S7n Cloud Services GmbH
Trained as a physicist in Dortmund and Eindhoven, Kurt always wanted to understand how things work. In IT, this meant using and contributing to Open Source. He initially applied this to the Linux Kernel. The fascination for technology was complemented by the thrill to work with and... Read More →
avatar for Felix Kronlage-Dammers

Felix Kronlage-Dammers

Member of the extended Board of Directors, Open Source Business Alliance e.V.
Felix has been building open source IT Infrastructure since the late 90s. Between then and now Felix was involved in various open source development communities. His interests range from monitoring/observability over infrastructure-as-code to building and scaling communities and companies... Read More →
Tuesday October 6, 2026 4:15pm - 4:40pm CEST
Panorama Hall

4:45pm CEST

Transparency Upstream, Evidence Downstream: Manufacturers and Open Source Under the CRA - William Janssen, TrustEngine
Tuesday October 6, 2026 4:45pm - 5:10pm CEST
The Cyber Resilience Act settled the legal side of the open source relationship: product responsibility stays with the manufacturer, stewards carry a light-touch regime, maintainers shielded from manufacturer-grade duties. The operational side is far less settled. Manufacturers must consume and interpret upstream security signals, but what that takes is rarely described from the manufacturer's seat.

This session walks that seat in concrete terms. From 11 September 2026, a manufacturer has 24 hours from awareness of active exploitation to file an early warning. Awareness at that speed is only dependable when machine-readable upstream signals (SBOMs, VEX, provenance, project health) are continuously correlated against what was actually shipped, per product, per configuration, with the record written as it happens, not assembled afterwards.

It also covers the return path: contributions rather than contracts, funding rather than warranties, and a defence of the transparency-versus-assurance boundary that keeps the voluntary model sustainable.

Presented three and a half weeks after the reporting duty goes live, it closes with first field observations from September.
Speakers
avatar for William Janssen

William Janssen

CTO & Head of Engineering, TrustEngine
William Janssen is CTO and Head of Engineering, and author of a Dutch-language book on the EU Cyber Resilience Act. He spent his career building and maintaining software products, from patient portals in healthcare to a PaaS platform, and knows what shipped software costs to support... Read More →
Tuesday October 6, 2026 4:45pm - 5:10pm CEST
Panorama Hall

5:15pm CEST

Digital Sovereignty for Businesses: The Case for FLOSS - Christian Grothoff, Taler Systems SA
Tuesday October 6, 2026 5:15pm - 5:40pm CEST
Digital sovereignty has become a strategic concern for businesses of all sizes. Dependence on a small number of technology providers can create operational, economic, and cybersecurity risks.

This talk examines digital sovereignty from a business perspective and argues that FLOSS is not merely
a technical or ideological choice, but a practical tool for
resilience, competition, and strategic autonomy. We will explore how FLOSS helps organizations preserve freedom of action, reduce lock-in risks, improve transparency, and maintain control over their digital infrastructure.

Finally, we will examine a frequently overlooked aspect of digital
sovereignty: payments. While open-source solutions now exist across much of the technology stack, businesses often encounter proprietary dependencies at the very point where commercial activity occurs.

The workshop part is designed to demonstrate how concepts such as openness, interoperability, privacy, and freedom from platform lock-in can be applied to payment systems, and to spark discussion about what true digital sovereignty means for businesses.
Speakers
avatar for Christian Grothoff

Christian Grothoff

Prof., Taler Systems SA
Christian Grothoff is professor for computer network security at the Bern University of Applied Sciences, researching future Internet architectures. He is a GNU maintainer and co-founder of Taler Systems SA and Anastasis SARL.
Tuesday October 6, 2026 5:15pm - 5:40pm CEST
Panorama Hall
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.