Loading…
19 September 2024
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SOSS Community Day Europe 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central Europe Summer Time (CEST). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
strong>Lightning Talks [clear filter]
Thursday, September 19
 

12:35 CEST

Rules of Engagement for Forking a Dependency - Chris Swan, Atsign
Thursday September 19, 2024 12:35 - 12:45 CEST
You got the CVE notification, but there's no fix yet. Customers GUACing your SBOMs are worried. Should you fork? This presentation will run through the rules of engagement we've used at Atsign when these situations arise, which aim to balance good community citizenship with making sure stuff gets fixed.
Speakers
avatar for Chris Swan

Chris Swan

Engineer, Atsign
Chris Swan is an Engineer at Atsign, building the atPlatform, a technology that is putting people in control of their data and removing the frictions and surveillance associated with today’s Internet. He was previously a Fellow at DXC Technology where he held various CTO roles... Read More →
Thursday September 19, 2024 12:35 - 12:45 CEST
Room 3.16-3.17

12:35 CEST

The Current State of Open Source Security Compliance Tooling Is … Well, Sad. - Philippe Ombredanne, AboutCode
Thursday September 19, 2024 12:35 - 12:45 CEST
There's an explosion of proprietary tools promising to resolve each and every software supply chain issue. But, none of these provide practical, reasonable, or affordable solutions to 1) massively improve the security posture of software teams and 2) comply with regulatory requirements. Software teams of all sizes continue to struggle navigating the complex network of tools and databases claiming to fix everything, especially with the explosion of reported CVEs and corresponding meltdown of processing these CVEs in the NVD. Open source tools are lagging and as an open source community, we can do better. In this talk, Philippe will present practical approaches to do something that works - using readily available OpenSSF projects, open source tools, and open data - to make compliance obtainable and automated with robust software supply chain security processes.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

ScanCode maintainer and CTO, nexB Inc., AboutCode.org and nexB Inc.
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
Thursday September 19, 2024 12:35 - 12:45 CEST
Room 3.29-3.30

15:05 CEST

Secure Coding Guide for Python - David Mather & Bart Karas, Ericsson
Thursday September 19, 2024 15:05 - 15:15 CEST
Python is an incredibly popular programming language and the language of choice for countless open source projects, ranging from hobbyist projects, via entire cloud virtualization frameworks (e.g. OpenStack), to being a key enabler for a large portion of AI and ML tooling (e.g. PyTorch). Helping these Python developers to securely master their programming challenges has a concrete benefit to the security of this vibrant open source ecosystem. The OpenSSF Best Practices Working Group has recently adopted a new initiative which aims to create a Secure Coding Guide for Python. Structured around Mitre's CWE framework, the guide provides tangible advice for a wide range of programming challenges, including executable code examples. These code snippets aim to allow developers to build a better understanding by enabling experimentation with concrete implementations while also constituting a proving ground for tool-based detection of weaknesses and vulnerabilities. In this brief presentation, Georg and Helge will provide an overview of the guide, its current state and its roadmap. We explicitly aim to solicit feedback from the Python community to further improve the guide.
Speakers
avatar for David Mather

David Mather

Engineer, Ericsson
David Mather is a Software Engineer and Lead Product Owner at Ericsson, where they specialize in designing and developing cutting-edge telecommunications software solutions. He has a master’s degree in cybersecurity, a bachelor’s degree in computer science and several years of... Read More →
avatar for Bartlomiej Karas

Bartlomiej Karas

Software Engineer, Ericsson
Bartlomiej Karas is a Software Engineer based in Ericsson, Athlone in Ireland where he works on the Ericsson Network Manager on Cloud deployments. During his time at Ericsson, Bart has gained knowledge of a wide variety of concepts and technologies including Kubernetes, microservices... Read More →
Thursday September 19, 2024 15:05 - 15:15 CEST
Room 3.16-3.17

15:05 CEST

Web Developer Security: Best Practices & Beyond - Daniel Appelquist, Samsung
Thursday September 19, 2024 15:05 - 15:15 CEST
Last year I co-chaired a workshop called "Secure the Web Forward" that brought together web and security professionals to “drive developer awareness and adoption of Web security standards & practices.” This session will overview the latest developments in web developer security, including new activities spawned by that workshop. We'll cover latest security-related technologies in the platform as well as work happening in new W3C community and interest groups in conjunction with the OpenSSF Best Practices working group.
Speakers
avatar for Daniel Appelquist

Daniel Appelquist

Open Source Strategist, Samsung
Dan Appelquist is Open Source Strategist at Samsung Open Source Group. He is a web & mobile industry veteran and long-time participant and leader in open source and open standards. He has been co-chair of the W3C Technical Architecture Group for the last ten years. He was an early... Read More →
Thursday September 19, 2024 15:05 - 15:15 CEST
Room 3.29-3.30
 
  • Filter By Venue
  • Filter By Type
  • Session Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.