Loading…
Attending this event?
October 22-23, 2024 | Atlanta, Georgia USA
View More Details & Registration

The Sched app allows you to build your schedule but is separate from your event registration. You must be registered for SOSS Fusion 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Eastern Daylight Saving Time. To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
OSPOs + Security clear filter
Tuesday, October 22
 

4:45pm EDT

How to Scale InnerSource Adoption in Regulated Industries - Joseph Zang, Fannie Mae
Tuesday October 22, 2024 4:45pm - 5:00pm EDT
Join me, Joseph Zang, on a journey through the complexities, pitfalls, and triumphs of scaling InnerSource adoption in the highly regulated Industry. As the InnerSource Community Lead Advocate, I've navigated the intricate landscape of regulatory constraints and organizational resistance to nurture a culture of collaboration leading to innovation and program maturity. In this session, I'll share my experiences (the good and not so good), and relay my insights on how to effectively implement InnerSource practices within regulated environments. Here's what to expect: Starting the InnerSource Journey Jumping Regulatory Hurdles Cultural Transformation Building the Right Infrastructure InnerSource in Practice This session is a candid glimpse at the challenges and rewards of championing InnerSource adoption in a regulated FinTech environment. Observe the practical strategies that worked for us, the obstacles we overcame (the ones we didn’t), and the hacks we discovered along the way as our InnerSource initiative matures.
Speakers
avatar for Joseph Zang

Joseph Zang

Lead Associate for InnerSource Advocacy, Fannie Mae
Joseph Zang is currently the InnerSource Lead Associate at Fannie Mae, where he champions innovation and enhances the developer experience. Passionate about the collaborative and equitable aspects of Open Source and InnerSource, Joe is dedicated to impactful, empathetic engineering... Read More →
Tuesday October 22, 2024 4:45pm - 5:00pm EDT
Skelton
 
Wednesday, October 23
 

10:35am EDT

Scorecard at Scale: Old and New Possibilities for Lifting Security on All Repositories - Jeff Mendoza, Kusari & Stephen Augustus, Cisco Systems, Inc.
Wednesday October 23, 2024 10:35am - 11:05am EDT
OpenSSF Scorecard assesses the security posture of a git repository and produces an overall score. This has proven useful for organizations to improve the security of their many repositories overall. However, this task is not a small undertaking. The act of running Scorecard, collecting the result, and interpreting the results is complex and can be done in different ways. This presentation covers multiple strategies for accomplishing Scorecard at Scale, including some new possibilities from the Scorecard team. Options include the Scorecard API, Scorecard Action, Scorecard Monitor, and Allstar. We will explore setup, execution, and results format for these options, then dig into extracting actionable insights from results as well.
Speakers
avatar for Stephen Augustus

Stephen Augustus

Head of Open Source, Cisco Systems, Inc.
Stephen is the Head of Open Source at Cisco, working within the Strategy, Incubation, & Applications (SIA) organization. Across the wider LF (Linux Foundation) ecosystem, Stephen has the pleasure of serving as a member of the OpenSSF Governing Board, the OpenAPI Initiative Business... Read More →
avatar for Jeff Mendoza

Jeff Mendoza

Software Engineer, Kusari
Jeff is an OpenSSF Scorecard Steering Committee member, and a maintainer on both the Allstar and GUAC projects. He also Co-Chairs the OpenSSF Securing Critical Projects Working Group. Jeff is a software engineer at Kusari, focused on Open Source, Cloud Native, and Supply Chain Security... Read More →
Wednesday October 23, 2024 10:35am - 11:05am EDT
Skelton

11:10am EDT

Ace of Base: Meeting the OpenSSF Security Baseline with Minder - Adolfo García Veytia, Stacklok
Wednesday October 23, 2024 11:10am - 11:40am EDT
The OpenSSL Security Baseline proposes a framework for a common security posture across open source projects. The baseline requirements are designed to match the OpenSSF's project lifecycle: each level has been designed to provide increasing levels of protection with as little effort as possible. They range from secure repository configuration to the production of security metadata such as SBOMs and SLSA attestations. These requirements may sound daunting but the path forward is bright! The OpenSSF community has been working hard to create tools, specifications, and libraries to help harden the global software supply chain. While we have built amazing tooling to automate compliance, orchestration can still be challenging. Understanding at scale which resources are falling short of the baseline expectations needs coordination and remediation. Luckily this is where Minder comes in! Minder is an open source platform that monitors your repositories, builds, and artifacts to ensure they match a declared security posture. In contrast to other tools, it reconciles the state of your resources to match your desired state. Join Puerco for a live demo of meeting baseline compliance!
Speakers
avatar for Adolfo García Veytia

Adolfo García Veytia

Staff Software Engineer, Stacklok
Adolfo García Veytia (@puerco) is a software engineer with Stacklok. He is one of the Kubernetes SIG Release Technical Leads, actively on the Release Engineering team. He specializes in improvements to automation behind the Kubernetes release process. He is also the creator OpenVEX... Read More →
Wednesday October 23, 2024 11:10am - 11:40am EDT
Skelton
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.