Loading…
11-12, August 2026
Seoul, South Korea
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Korea 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Korea Standard Time (KST), UTC +9. To see the schedule in your preferred timezone, please select from the drop-down menu to the right.
Venue: Chrysanthemum clear filter
arrow_back View All Dates
Tuesday, August 11
 

11:00 KST

SBOMs Aren't Enough. Secure Your Software Supply Chain End-To-End - Yongjae Chung, New York University Secure Systems Lab & Justin Cappos, New York University
Tuesday August 11, 2026 11:00 - 11:30 KST
You probably heard that SBOMs are helpful, but did you know that an SBOM only addresses a fraction of what can go wrong in your software supply chain? The SLSA (Supply Chain Levels for Software Artifacts) specification identifies 9 distinct threat areas, spanning from source code, all the way to package distribution. Most development teams address one or two of these and call it a day, leaving gaps that real-world attacks like SolarWinds and Log4J have already exploited. We understand that it is difficult to cover all aspects when it comes to the software supply chain.

How about we make this much easier? In this talk, we will present an overview of the modern software supply chain threat model, and show how you can provide integrity throughout the whole process of your software development life cycle. We will introduce an easy-to-setup, end-to-end open source stack, built from frameworks and tools within the CNCF/OpenSSF ecosystem.
Speakers
avatar for Justin Cappos

Justin Cappos

Professor, New York University
I am a professor at NYU who has been working on software supply chain security for more than 20 years. I am a maintainer / creator of the TUF, Uptane, and in-toto projects, which are all under the LF.
avatar for Yongjae Chung

Yongjae Chung

Master's Student, New York University Secure Systems Lab
Yongjae is a Master's student at New York University. He is a contributor to gittuf, an incubating project at Open Source Security Foundation.
Tuesday August 11, 2026 11:00 - 11:30 KST
Chrysanthemum

11:40 KST

One Binary, Every Package Manager: Shipping a Rust CLI To PyPI, Npm, Homebrew, Winget, and Beyond - Ajit Kumar, Independent
Tuesday August 11, 2026 11:40 - 12:10 KST
Most dev tools die in obscurity because installation friction kills adoption before the first command is run. This talk provides a battle-tested playbook for solving that problem using evnx—a Rust CLI for validating and secret-scanning `.env "files"—as a real-world case study.

Launched in early 2026, evnx achieved thousands of cross-ecosystem downloads within weeks by treating distribution as a first-class engineering concern. The session breaks down a complete distribution matrix:

Registry Packaging: Using crates.io as a source of truth, Maturin for native Python wheels, and npm wrappers for platform-specific binaries.
OS Package Managers: Automating Homebrew formulas via cargo-dist, plus Scoop and Winget submissions.
Developer Integration: GitHub Actions with SARIF output, pre-commit hooks, and lightweight Docker CI images.
Supply-Chain Security: Leveraging PyPI Trusted Publishing (OIDC), provenance attestations, and cosign for signed containers.

Attendees will receive reusable GitHub Actions workflows and manifest templates from the public evnx repo to ship any Rust CLI across ecosystems without sacrificing security or maintainer sanity.
Speakers
avatar for Ajit Kumar

Ajit Kumar

Researcher and Software Developer

Tuesday August 11, 2026 11:40 - 12:10 KST
Chrysanthemum

13:35 KST

Panel: Realizing Sovereign AI: Strategies for Korea’s Tech Sovereignty and AI Independence Via Open Source - Yongkook Kim, IBM; Hong-Seok Kim, Rebellions; Rosa (Hyun Kyong) Lee, Korea Information Society Development Institute & Carlos Costa, IBM Research
Tuesday August 11, 2026 13:35 - 14:05 KST
When global AI development being centralized around proprietary "black-box" models, the demand for Sovereign AI has become a national priority for many countries, including South Korea. True sovereignty requires more than just local data or local LLMs; it demands independence across the entire stack—from silicon up to the software services, as well as AI model itself. This panel challenges the misconception that global technology leaders are incompatible with national goals, demonstrating instead how open-source collaboration is the only viable path to technical and data independence as foundation for Sovereign AI.
Speakers
avatar for Alex Kim

Alex Kim

CTO for Strategic Ecosystem Partnership at IBM, IBM
Yongkook (Alex) is an OSS advocate, and a tech leader with 25+ years in R&D and IT architecture. He started as a security chip engineer at IBM Poughkeepsie, then worked as an enterprise IT architect for financial clients like Morgan Stanley and DTCC. Alex co-founded the Linux Foundation's... Read More →
avatar for Hong-Seok Kim

Hong-Seok Kim

Chief Software Architect, Rebellions
Hong-Seok is the Chief Software Architect at Rebellions, an AI accelerator startup based in Korea. He is also one of the maintainers for PyTorch Korea, leading its Core Special Interest Group. Before joining Rebellions, he was at Google as an Engineering Director and worked on it... Read More →
avatar for Rosa (Hyun Kyong) Lee

Rosa (Hyun Kyong) Lee

AI Social Policy Group Leader, Research Fellow, Korea Information Society Development Institute,
Dr. Lee, is a AI Social Policy Group Leader at the Department of AI Policy Research, the Korea Information Society Development Institute (KISDI). Her research area covers policy for human-centered artificial intelligence (AI), AI ethics education, digital transformation and digital... Read More →
avatar for Carlos Costa

Carlos Costa

Distinguished Engineer, IBM Research
Dr. Costa is an IBM Distinguished Engineer leading efforts to build a next-generation cloud-native platform for AI. He has been involved in multiple projects in the areas of large-scale AI/ML, HPC and analytics, including the BlueGene/Q system, the Active Memory Cube (AMC) architecture... Read More →
Tuesday August 11, 2026 13:35 - 14:05 KST
Chrysanthemum

14:15 KST

From Contribution To Culture: 14 Years of Building an OSPO That Outgrew Itself - Darae Ahn, Samsung Electronics
Tuesday August 11, 2026 14:15 - 14:45 KST
Over the past decade, many organizations have established OSPOs to manage open source usage and compliance. However, building a sustainable open source culture requires more than policies and processes.

This session shares a 14-year journey of an OSPO that evolved from a contribution-focused group into a broader organization encompassing usage, compliance, and internal enablement.

It explores how open source practices were embedded into engineering culture through project incubation, developer engagement, and internal leadership programs. Over time, these efforts led to a shift where open source activities became self-sustaining, with teams proactively initiating projects and contributions.

The session also reflects on an unexpected outcome: talent mobility. As internal open source leaders grew, many moved on to new opportunities, revealing both retention challenges and the broader impact of cultivating open talent.

Key lessons include the balance between control and autonomy, the role of leadership in cultural change, and how open source can be viewed not only as a compliance requirement, but as a long-term investment in culture and organizational brand.
Speakers
avatar for Darae Ahn

Darae Ahn

Staff Engineer, Open Source Group, Samsung Electronics
I have over 12 years of experience in open source at Samsung Electronics, where I have built and scaled open source programs. My work spans contribution, policy, compliance, and tooling, strengthening organizational capabilities.

I also participate in governance discussions within the community, focusing on how to sustain open source values in evolving development environments... Read More →
Tuesday August 11, 2026 14:15 - 14:45 KST
Chrysanthemum

14:55 KST

How AI Is Changing Open Source Communities: Lessons From OpenEuler - Jianmin Wang, openEuler Community
Tuesday August 11, 2026 14:55 - 15:25 KST
Artificial Intelligence is reshaping how software is developed and maintained. From code generation to automated reviews, AI tools are increasingly influencing how open source communities collaborate. This also introduces new challenges, including how to handle AI-generated contributions, maintain trust and code quality, and define governance for AI-assisted workflows.

In this session, we share experiences from the openEuler community in integrating AI into development processes, including AI-assisted code review, package maintenance, and community guidelines for AI usage, as well as work on frameworks such as Intelligence BooM.

We will discuss how these changes affect contributor workflows, what challenges maintainers face in practice, and what approaches have worked so far. The goal is to provide practical reference points for other open source communities exploring similar directions.
Speakers
avatar for Jimmie Wang

Jimmie Wang

Senior Software Engineer, openEuler Community
Jimmie Wang has over a decade of experience in system software and open source, focusing on operating systems, privacy and data, AI Security. He is a core contributor to the openEuler community, serving on the Technical Committee and maintaining multiple SIGs. He is a frequent speaker... Read More →
Tuesday August 11, 2026 14:55 - 15:25 KST
Chrysanthemum

15:55 KST

Skills-as-Packages: A Package Manager for AI Agent Skills - Brahada Srinivas, Amazon
Tuesday August 11, 2026 15:55 - 16:25 KST
AI agents like Claude Code, Cursor, and Codex learn libraries via SKILL.md files, but these skills are currently unversioned, ungoverned, and unshared. We solved code dependency management with pip and npm — now it's time to solve it for AI knowledge.
This talk presents an open-source, package-manager-style system for agent skills. Skills are linked to their packages, versioned with semver, declared in skills.toml, and locked via skills-lock.toml — just like regular dependencies.
The CLI (skills add, install, lock, publish) feels native to any developer using pip or uv.
We'll cover:

The SKILL.md open standard (YAML frontmatter + Markdown) — model-agnostic and runtime-agnostic
Manifest format supporting version constraints, inheritance, and monorepo scoping
Resolver that enforces constraint narrowing across org hierarchies
Registry with publishing, discovery, approval workflows, and security scanning
Real cases where this prevented production incidents by keeping agents on correct, up-to-date patterns

Live demo: Add a skill, resolve dependencies, publish it, and watch a new engineer's agent instantly get the right knowledge - no onboarding docs required.
Speakers
avatar for Brahada Srinivas

Brahada Srinivas

Ms, Amazon
Brahada Srinivas is a senior engineer working at Amazon focused on developer productivity and AI-assisted workflows. She designs systems at the intersection of package management and AI agent governance - making sure agents don't just write code, but write the right code. He is the... Read More →
Tuesday August 11, 2026 15:55 - 16:25 KST
Chrysanthemum

16:35 KST

Computer Programming Is Dead; Long Live AI-First Programming - Stephen Chin, Neo4j & Cassandra Chin, Independent
Tuesday August 11, 2026 16:35 - 17:05 KST
Computer science graduates are facing an increasingly difficult job market. Recent data shows a sharp decline in employment outcomes for computer science majors, highlighting the mismatch between what universities teach and what employers now demand. The traditional model of teaching syntax first and hoping students eventually build something useful is no longer working. In this keynote we argue that programming as we knew it is effectively dead. The future lies in AI-First programming, built on the simple loop of try, learn, and grow. Learners try building code with AI assistance, learn by unpacking the generated code and asking AI for detailed explanations, and grow by testing and extending real applications. This loop not only builds confidence but also ensures we grow the generation of AI engineers that companies are desperate to hire.
Speakers
avatar for Stephen Chin

Stephen Chin

VP of Developer Relations, Neo4j
Stephen Chin is VP of Developer Relations at Neo4j and author of numerous titles including the upcoming GraphRAG: The Definitive Guide for O'Reilly. He has given keynotes and main stage talks at numerous conferences around the world including AI Engineer Summit, AI DevSummit, Devoxx... Read More →
avatar for Cassandra Chin

Cassandra Chin

Java Champion, Book Author, Keynote Speaker, Kids Workshop Instructor, Independent
Cassandra Chin is a keynote speaker, book author, podcast host, children's workshop instructor, and a computer science student. She has been teaching technology kids workshops at international conferences since she was 13 years old and is passionate about helping allow women, minorities... Read More →
Tuesday August 11, 2026 16:35 - 17:05 KST
Chrysanthemum

17:15 KST

GitAIOps: A 4-Layer Architecture for Predictable AI-Assisted Operations - Hoon Jo, Megazone
Tuesday August 11, 2026 17:15 - 17:45 KST
AI agents have no memory between sessions. Every conversation starts from zero. Git becomes the only persistent memory an AI agent can rely on. GitAIOps is the pattern built on this principle: Git is the memory, and a 4-layer architecture defines what goes into that memory.

I applied this to a production migration: 15 Helm releases, Kafka ZooKeeper-to-KRaft, Redis-to-Valkey, full observability stack rebuild. The question: what does Git need to contain so any AI session picks up where the last one left off?

The answer is a 4-layer Git structure, each layer born from a production failure.
Layer 1: Human plans in Git (36 files, 23,854 lines). Too verbose for AI.
Layer 2: Distilled AI context in Git (6 files, 1,254 lines). 19:1 compression as a project state dashboard.
Layer 3: Command Guardrails in Git (117 files). Enforced ordering, no AI-generated commands.
Layer 4: Locked values in Git (30 files). Zero interpretation, reviewed like code.

Every AI action reads from Git, executes, and commits back. The loop is closed.

DEV: 2 weeks → 2 days. PROD: 1 week → 1 day. The session covers the architecture, each layer's failure, and real production artifacts.
Speakers
avatar for Hoon Jo

Hoon Jo

AI & Cloud-Native Engineer, Megazone
Hoon Jo is a CNCF Ambassador and Kubestronaut who has spoken at KubeCon North America, Europe, China, and India across multiple years. He is the author of multiple books on Kubernetes and AI-assisted operations. His current work focuses on building operational patterns where AI agents... Read More →
Tuesday August 11, 2026 17:15 - 17:45 KST
Chrysanthemum
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -