How Secure Is Academic Open Source? Insights From the UC OSPO Network - Juanita Gomez

Presenters Juanita Gomez Source OpenSource SecurityCon NA 2025 Unveiling the Security Secrets of Academic Open Source 🛡️: A Deep Dive into UC System Projects Ever wondered about the security of the open source projects born from our academic institutions? Juanita, a PhD candidate at UC Santa Cruz and a dedicated Python community member, recently pulled back the curtain on the open source landscape within the University of California (UC) system. Her groundbreaking research reveals a picture that’s both fascinating and, frankly, a little concerning when it comes to security best practices. Let’s dive into what she discovered! 🚀 ...

November 24, 2025 · 6 min

Lightning Talk: Where Should Source Attestations Live? Exploring Storage Strategies - Billy Lynch

Presenters Billy Lynch Source OpenSource SecurityCon NA 2025 Where Do Your Source Attestations Live? Navigating the Labyrinth of Metadata 🗺️ Hey tech enthusiasts! Ever felt like you’re drowning in a sea of metadata, wondering where exactly to stash those crucial source attestations? You’re not alone! At a recent lightning talk, Billy Lynch from Chain Guard dove deep into this very question, exploring strategies for storing and discovering these vital pieces of information. Let’s break down the key takeaways and ponder the future of source attestation storage. 💡 ...

November 24, 2025 · 5 min

Multi-messenger Security: Adaptive Kubernetes SOC... Constanze Roedig, Ben Hirschberg & Dom Delnano

Presenters Constanze Roedig Ben Hirschberg Dom Delnano Source OpenSource SecurityCon NA 2025 Beyond the Buzzwords: Unveiling an Adaptive eBPF Security Powerhouse for Real-World Threats 🚀 In the ever-evolving landscape of cybersecurity, staying ahead of sophisticated threats often feels like chasing a phantom. Traditional security operations centers (SOCs), while essential, can often buckle under the weight of performance overhead, overwhelming data volumes, and the persistent challenge of truly fast and accurate detection. But what if there was a way to fuse the power of observability with the precision of security, creating an adaptive defense system that learns and evolves with the threats it faces? ...

November 24, 2025 · 6 min

OSPS Baseline: Improving Your Project Security the Easy Way - Ben Cotton, Kusari

Presenters Ben Cotton Source OpenSource SecurityCon NA 2025 Level Up Your Open Source Security: The OpenSSF Project Security Baseline Explained 🚀 Hey tech enthusiasts! 👋 Ever felt a little overwhelmed by the sheer volume of security advice out there for open source projects? You’re not alone! The good news is, there’s a fantastic initiative making it easier than ever for maintainers to bolster their project’s security, even without a dedicated security team. Let’s dive into the OpenSSF Project Security Baseline and see how it’s revolutionizing open source security hygiene. ...

November 24, 2025 · 4 min

Rewiring Cilium: Operator-Driven Scale and Security With C... Shreya Jayaraman & Tamilmani Manoharan

Presenters Shreya Jayaraman Tamilmani Manoharan Source CiliumCon NA 2025 Supercharging Kubernetes Networking: How Cilium Endpoint Slices Conquer Scale! 🚀 Ever felt the pinch of Kubernetes scaling limitations? You’re not alone! Microsoft’s engineering wizards, Tamilmani and Shreya, recently pulled back the curtain on a revolutionary feature that’s transforming Kubernetes networking: Cilium Endpoint Slices. Forget those agonizingly slow pod startups and API server meltdowns. This is the deep dive you need to understand how Cilium Endpoint Slices are not just fixing problems, but paving the way for truly massive Kubernetes clusters. ...

November 24, 2025 · 8 min