OpenSSF 2025
A full day on securing the open-source software supply chain, co-located with KubeCon + CloudNativeCon India in Hyderabad.
The Open Source Security Foundation (OpenSSF) is a community of software developers, security engineers, and others working together to secure open-source software for the greater public good. On August 4, 2025, that community gathered in Hyderabad for Community Day India, a single-track day of talks and keynotes run alongside KubeCon + CloudNativeCon India.

What OpenSSF is
The OpenSSF seeks to make it easier to sustainably secure the development, maintenance, release, and consumption of open-source software: fostering collaboration, establishing best practices, and building tooling. In practice that means the supply chain, the part of security most people ignore right up until a dependency they never chose turns out to be the thing that gets them.
It is a community as much as a foundation, and the home of a lot of tooling you have probably relied on without noticing: Sigstore for signing, SLSA for build provenance, Scorecard for repository health, and a growing body of SBOM and vulnerability-exchange work. Community Day is where the people behind those turn up in one room.
A day about the supply chain
The schedule read like a map of everything currently hard about trusting code you did not write. Talks on going beyond SBOM generation to actual SBOM quality and compliance, malicious-package scanning, enforcing supply-chain policy from code all the way down to the Linux kernel, and automating security policy across whole GitHub organizations with Allstar.
There was a strong forward-looking thread too: the migration to post-quantum cryptography and a CBOM, a cryptographic bill of materials, to actually track it; VEX for smarter vulnerability triage; and policy-as-code engines for enforcement. Keynotes bracketed the day, from OpenSSF's own Ram Iyengar to Carrier and Red Hat on keeping very long-lived, very regulated software secure. My favourite title, and a fair summary of the moment: 'Vibe Coding With AI Is Cool Until You Get Hacked.'



The sessions
One single track, so nobody had to choose. These are the talks and keynotes that made up the day, each linking to its page on the schedule.
- So You Want Runtime Security on Podman?Rishabh Soni, Accuknox
- Vibe Coding With AI Is Cool Until You Get HackedAchanandhi M, Keploy
- The Migration To Post-Quantum Cryptography: Open-Source Innovations and InteroperabilityTony Chen, Keyfactor
- How Insecure Defaults Led To Undetected Supply Chain Incident: A CI/CD Security NightmareVipul Gupta, Balena
- Keynote: Keeping Methuselah Up To DateRyan Ware, Carrier Global
- Keynote: Visibility, Control & Agility: The CBOM Path to Cryptographic ResilienceAnitha Natarajan, Red Hat
- Malicious Package Scanning Using VetTeja Kummarikuntla, Harness
- Going Beyond SBOM Generation: Ensuring Quality, Compliance, and Real Security ReadinessVivek Kumar Sahu, Interlynk
- From Code To Kernel: Enforcing Supply Chain Security for Linux DistributionsAditya Soni, Forrester Research
- Allstar in Action: Automating Security Policies for GitHub OrganizationsAbhinav Sharma, KodeKloud
- Policy-as-Code: Choosing the Right Engine for Effective Validation and EnforcementRuhika Bulani, Spyderbat & Harsh Thakur, Nuon
- Enhancing Vulnerability Triage With VEX: A GSoC Journey in CVE Binary ToolSanskar Sharma, Nirmata
- Chaos Engineering for Security: Breaking Systems To Strengthen DefensesPratik Mahalle, Keploy
- Debian Inspired Container-first Linux DistroAbhishek Anand & Abhimanyu Dhamija, KoalaLab
- UEFI Secure Boot in LinuxSumeet Pawnikar, Cisco
The community in the room
The talks get recorded; the conversations around them do not. Sitting next to someone who maintains a tool you use, arguing about SBOM quality over coffee, meeting the people whose GitHub handles you already know. That is what a Community Day is actually for.
OpenSSF is a community more than a product, and days like this are where it gathers in person: maintainers, security engineers, and the people trying to make the open-source supply chain a little harder to attack. Worth the trip to Hyderabad for that alone.
