OSPS Baseline: Improving Your Project Security the Easy Way - Ben Cotton, Kusari

Presenters Ben Cotton Source OpenSource SecurityCon NA 2025 Level Up Your Open Source Security: The OpenSSF Project Security Baseline Explained 🚀 Hey tech enthusiasts! 👋 Ever felt a little overwhelmed by the sheer volume of security advice out there for open source projects? You’re not alone! The good news is, there’s a fantastic initiative making it easier than ever for maintainers to bolster their project’s security, even without a dedicated security team. Let’s dive into the OpenSSF Project Security Baseline and see how it’s revolutionizing open source security hygiene. ...

November 24, 2025 · 4 min

Transparency Exchange API: Where To Find Product SBOM? - Pavel Shukhman, Reliza

Presenters Pavel Shukhman Source OpenSource SecurityCon NA 2025 Demystifying the Software Supply Chain: Your Guide to the Transparency Exchange API 🚀 Ever felt like you’re playing a guessing game when it comes to the “ingredients” in your software? You’re not alone! In today’s complex digital world, understanding what goes into our products isn’t just good practice; it’s becoming a necessity, especially with new regulations like the EU CRA on the horizon. This is where the revolutionary Transparency Exchange API (TX API) steps in, promising to transform how we manage and share Software Bills of Materials (SBOMs). ...

November 24, 2025 · 5 min

The State of Git Security With SLSA and Gittuf - Patrick Zielinski & Aditya Sirish A Yelgundhalli

Presenters Patrick Zielinski Aditya Sirish A Yelgundhalli Source OpenSource SecurityCon NA 2025 Fortifying Your Code: A Deep Dive into SLSA and GitHub for Unbreakable Software Supply Chains 🚀 In today’s interconnected digital world, the integrity of our software supply chain is paramount. We’ve all heard the alarming stories: compromised GitHub actions, hijacked organizations, and even vulnerabilities in widely used projects like PHP and Juniper. These incidents underscore a critical truth: a breach at the source code level can have devastating ripple effects. But fear not! The open-source community is tirelessly working to build stronger defenses, and at the forefront of this effort are SLSA and GitHub. ...

November 24, 2025 · 6 min

From Adoption to Innovation: LinkedIn’s SPIRE Journey - Junyuan Zeng & Wei Zhang, LinkedIn

Presenters Junyuan Zeng Wei Zhang Source OpenSource SecurityCon NA 2025 LinkedIn’s Identity Revolution: From Fragile PKI to Spire-Powered Security! 🚀 Ever feel like your security infrastructure is a house of cards? 🃏 That’s exactly where LinkedIn found itself a few years ago. Their homegrown Public Key Infrastructure (PKI) system, built on a basic Python server, was buckling under the weight of their massive microservice architecture. It was a system that screamed “legacy” – lacking scalability, standard identity formats, and the ability to efficiently manage certificates. Imagine trying to build a skyscraper on a sandcastle foundation! 🏗️ ...

November 24, 2025 · 7 min

Lightning Talk: AIxCC Results and New Open Source AI Projects To Help Secure Open Sou... Jeff Diecks

Presenters Jeff Diecks Source OpenSource SecurityCon NA 2025 AI Cyber Challenge: Revolutionizing Open Source Security with Intelligent Automation 🚀 The world of open-source software is the backbone of our digital infrastructure, but it’s also a prime target for cyber threats. For years, the challenge has been not just finding vulnerabilities, but fixing them efficiently. Enter the AI Cyber Challenge (AICC), a groundbreaking initiative that brought together cutting-edge AI and the open-source community to tackle this critical problem head-on. ...

November 24, 2025 · 5 min