← Misc
Hyderabad, India · August 4, 2025

OpenSSF 2025

A full day on securing the open-source software supply chain, co-located with KubeCon + CloudNativeCon India in Hyderabad.

The Open Source Security Foundation (OpenSSF) is a community of software developers, security engineers, and others working together to secure open-source software for the greater public good. On August 4, 2025, that community gathered in Hyderabad for Community Day India, a single-track day of talks and keynotes run alongside KubeCon + CloudNativeCon India.

OpenSSF Community Day India 2025 attendee badge held up in front of the stage

What OpenSSF is

The OpenSSF seeks to make it easier to sustainably secure the development, maintenance, release, and consumption of open-source software: fostering collaboration, establishing best practices, and building tooling. In practice that means the supply chain, the part of security most people ignore right up until a dependency they never chose turns out to be the thing that gets them.

It is a community as much as a foundation, and the home of a lot of tooling you have probably relied on without noticing: Sigstore for signing, SLSA for build provenance, Scorecard for repository health, and a growing body of SBOM and vulnerability-exchange work. Community Day is where the people behind those turn up in one room.

A day about the supply chain

The schedule read like a map of everything currently hard about trusting code you did not write. Talks on going beyond SBOM generation to actual SBOM quality and compliance, malicious-package scanning, enforcing supply-chain policy from code all the way down to the Linux kernel, and automating security policy across whole GitHub organizations with Allstar.

There was a strong forward-looking thread too: the migration to post-quantum cryptography and a CBOM, a cryptographic bill of materials, to actually track it; VEX for smarter vulnerability triage; and policy-as-code engines for enforcement. Keynotes bracketed the day, from OpenSSF's own Ram Iyengar to Carrier and Red Hat on keeping very long-lived, very regulated software secure. My favourite title, and a fair summary of the moment: 'Vibe Coding With AI Is Cool Until You Get Hacked.'

A speaker at the podium addressing a full session roomA wide view of the session room with a speaker on stage and rows of attendeesAttendees seated in the session room

The sessions

One single track, so nobody had to choose. These are the talks and keynotes that made up the day, each linking to its page on the schedule.

The community in the room

The talks get recorded; the conversations around them do not. Sitting next to someone who maintains a tool you use, arguing about SBOM quality over coffee, meeting the people whose GitHub handles you already know. That is what a Community Day is actually for.

OpenSSF is a community more than a product, and days like this are where it gathers in person: maintainers, security engineers, and the people trying to make the open-source supply chain a little harder to attack. Worth the trip to Hyderabad for that alone.

Group photo of OpenSSF Community Day India 2025 attendees