Loading…
11-12, August 2026
Seoul, South Korea
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Korea 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Korea Standard Time (KST), UTC +9. To see the schedule in your preferred timezone, please select from the drop-down menu to the right.
Venue: Magnolia clear filter
arrow_back View All Dates
Tuesday, August 11
 

11:00 KST

SBOMs Aren't Enough. Secure Your Software Supply Chain End-To-End - Yongjae Chung, New York University Secure Systems Lab & Justin Cappos, New York University
Tuesday August 11, 2026 11:00 - 11:30 KST
You probably heard that SBOMs are helpful, but did you know that an SBOM only addresses a fraction of what can go wrong in your software supply chain? The SLSA (Supply Chain Levels for Software Artifacts) specification identifies 9 distinct threat areas, spanning from source code, all the way to package distribution. Most development teams address one or two of these and call it a day, leaving gaps that real-world attacks like SolarWinds and Log4J have already exploited. We understand that it is difficult to cover all aspects when it comes to the software supply chain.

How about we make this much easier? In this talk, we will present an overview of the modern software supply chain threat model, and show how you can provide integrity throughout the whole process of your software development life cycle. We will introduce an easy-to-setup, end-to-end open source stack, built from frameworks and tools within the CNCF/OpenSSF ecosystem.
Speakers
avatar for Justin Cappos

Justin Cappos

Professor, New York University
I am a professor at NYU who has been working on software supply chain security for more than 20 years. I am a maintainer / creator of the TUF, Uptane, and in-toto projects, which are all under the LF.
avatar for Yongjae Chung

Yongjae Chung

Master's Student, New York University Secure Systems Lab
Yongjae is a Master's student at New York University. He is a contributor to gittuf, an incubating project at Open Source Security Foundation.
Tuesday August 11, 2026 11:00 - 11:30 KST
Magnolia

11:40 KST

One Binary, Every Package Manager: Shipping a Rust CLI To PyPI, Npm, Homebrew, Winget, and Beyond - Ajit Kumar, Wellmatix
Tuesday August 11, 2026 11:40 - 12:10 KST
Most dev tools die in obscurity because installation friction kills adoption before the first command is run. This talk provides a battle-tested playbook for solving that problem using evnx—a Rust CLI for validating and secret-scanning `.env "files"—as a real-world case study.

Launched in early 2026, evnx achieved thousands of cross-ecosystem downloads within weeks by treating distribution as a first-class engineering concern. The session breaks down a complete distribution matrix:

Registry Packaging: Using crates.io as a source of truth, Maturin for native Python wheels, and npm wrappers for platform-specific binaries.
OS Package Managers: Automating Homebrew formulas via cargo-dist, plus Scoop and Winget submissions.
Developer Integration: GitHub Actions with SARIF output, pre-commit hooks, and lightweight Docker CI images.
Supply-Chain Security: Leveraging PyPI Trusted Publishing (OIDC), provenance attestations, and cosign for signed containers.

Attendees will receive reusable GitHub Actions workflows and manifest templates from the public evnx repo to ship any Rust CLI across ecosystems without sacrificing security or maintainer sanity.
Speakers
avatar for Ajit Kumar

Ajit Kumar

Senior Software Architect, Wellmatix

Tuesday August 11, 2026 11:40 - 12:10 KST
Magnolia

13:35 KST

Panel Session: Realizing Sovereign AI: Strategies for Korea’s Tech Sovereignty and AI Independence Via Open Source - Yongkook Kim & Priya Nagpurkar, IBM; Jae Lee, Rebellions; Alice Oh, KAIST
Tuesday August 11, 2026 13:35 - 14:05 KST
When global AI development being centralized around proprietary "black-box" models, the demand for Sovereign AI has become a national priority for many countries, including South Korea. True sovereignty requires more than just local data or local LLMs; it demands independence across the entire stack—from silicon up to the software services, as well as AI model itself. This panel challenges the misconception that global technology leaders are incompatible with national goals, demonstrating instead how open-source collaboration is the only viable path to technical and data independence as foundation for Sovereign AI.
Speakers
avatar for Alice Oh

Alice Oh

Endowed Professor, School of Computing & Head of the Global Cooperation Subcommittee of the Presidential Council on National AI Strategy, KAIST
Alice Oh is a KAIST ICT Endowed Professor in the School of Computing at KAIST and Head of the Global Cooperation Subcommittee of the Presidential Council on National AI Strategy. She received her PhD in Computer Science from MIT in 2008. Her major research area is at the intersection... Read More →
avatar for Priya Nagpurkar

Priya Nagpurkar

Vice President, AI-native Systems Research, IBM Research
Priya Nagpurkar is the Vice President of AI-native Systems research at I.B.M.'s T.J. Watson Research Center in New York. She leads a global team of systems and AI experts working on all interesting aspects of the AI platform -- from scalable, performant, and efficient deployment... Read More →
avatar for Jae Lee

Jae Lee

Head of Forward Deployed Engineering, Rebellions
Dr. Lee leads Forward Deployed Engineering at Rebellions, Korea's sovereign AI chip company, deploying its accelerators into datacenters through deep integration with open-source frameworks. He drives strategic implementation, technology enablement, and customer engagement to accelerate... Read More →
avatar for Alex Kim

Alex Kim

CTO for Strategic Ecosystem Partnership at IBM, IBM
Yongkook (Alex) is an OSS advocate, and a tech leader with 25+ years in R&D and IT architecture. He started as a security chip engineer at IBM Poughkeepsie, then worked as an enterprise IT architect for financial clients like Morgan Stanley and DTCC. Alex co-founded the Linux Foundation's... Read More →
Tuesday August 11, 2026 13:35 - 14:05 KST
Magnolia

14:15 KST

From Contribution To Culture: 14 Years of Building an OSPO That Outgrew Itself - Darae Ahn, Samsung Electronics
Tuesday August 11, 2026 14:15 - 14:45 KST
Over the past decade, many organizations have established OSPOs to manage open source usage and compliance. However, building a sustainable open source culture requires more than policies and processes.

This session shares a 14-year journey of an OSPO that evolved from a contribution-focused group into a broader organization encompassing usage, compliance, and internal enablement.

It explores how open source practices were embedded into engineering culture through project incubation, developer engagement, and internal leadership programs. Over time, these efforts led to a shift where open source activities became self-sustaining, with teams proactively initiating projects and contributions.

The session also reflects on an unexpected outcome: talent mobility. As internal open source leaders grew, many moved on to new opportunities, revealing both retention challenges and the broader impact of cultivating open talent.

Key lessons include the balance between control and autonomy, the role of leadership in cultural change, and how open source can be viewed not only as a compliance requirement, but as a long-term investment in culture and organizational brand.
Speakers
avatar for Darae Ahn

Darae Ahn

Staff Engineer, Open Source Group, Samsung Electronics
I have over 12 years of experience in open source at Samsung Electronics, where I have built and scaled open source programs. My work spans contribution, policy, compliance, and tooling, strengthening organizational capabilities.

I also participate in governance discussions within the community, focusing on how to sustain open source values in evolving development environments... Read More →
Tuesday August 11, 2026 14:15 - 14:45 KST
Magnolia

14:55 KST

How AI Is Changing Open Source Communities: Lessons From OpenEuler - Jianmin Wang, openEuler Community
Tuesday August 11, 2026 14:55 - 15:25 KST
Artificial Intelligence is reshaping how software is developed and maintained. From code generation to automated reviews, AI tools are increasingly influencing how open source communities collaborate. This also introduces new challenges, including how to handle AI-generated contributions, maintain trust and code quality, and define governance for AI-assisted workflows.

In this session, we share experiences from the openEuler community in integrating AI into development processes, including AI-assisted code review, package maintenance, and community guidelines for AI usage, as well as work on frameworks such as Intelligence BooM.

We will discuss how these changes affect contributor workflows, what challenges maintainers face in practice, and what approaches have worked so far. The goal is to provide practical reference points for other open source communities exploring similar directions.
Speakers
avatar for Jimmie Wang

Jimmie Wang

Senior Software Engineer, openEuler Community
Jimmie Wang has over a decade of experience in system software and open source, focusing on operating systems, privacy and data, AI Security. He is a core contributor to the openEuler community, serving on the Technical Committee and maintaining multiple SIGs. He is a frequent speaker... Read More →
Tuesday August 11, 2026 14:55 - 15:25 KST
Magnolia

15:55 KST

Skills-as-Packages: A Package Manager for AI Agent Skills - Brahada Srinivas, Amazon
Tuesday August 11, 2026 15:55 - 16:25 KST
AI agents like Claude Code, Cursor, and Codex learn libraries via SKILL.md files, but these skills are currently unversioned, ungoverned, and unshared. We solved code dependency management with pip and npm — now it's time to solve it for AI knowledge.
This talk presents an open-source, package-manager-style system for agent skills. Skills are linked to their packages, versioned with semver, declared in skills.toml, and locked via skills-lock.toml — just like regular dependencies.
The CLI (skills add, install, lock, publish) feels native to any developer using pip or uv.
We'll cover:

The SKILL.md open standard (YAML frontmatter + Markdown) — model-agnostic and runtime-agnostic
Manifest format supporting version constraints, inheritance, and monorepo scoping
Resolver that enforces constraint narrowing across org hierarchies
Registry with publishing, discovery, approval workflows, and security scanning
Real cases where this prevented production incidents by keeping agents on correct, up-to-date patterns

Live demo: Add a skill, resolve dependencies, publish it, and watch a new engineer's agent instantly get the right knowledge - no onboarding docs required.
Speakers
avatar for Brahada Srinivas

Brahada Srinivas

Senior Engineer, Amazon
Brahada Srinivas is a senior engineer working at Amazon focused on developer productivity and AI-assisted workflows. She designs systems at the intersection of package management and AI agent governance - making sure agents don't just write code, but write the right code. He is the... Read More →
Tuesday August 11, 2026 15:55 - 16:25 KST
Magnolia

16:35 KST

Computer Programming Is Dead; Long Live AI-First Programming - Stephen Chin, Neo4j & Cassandra Chin, Independent
Tuesday August 11, 2026 16:35 - 17:05 KST
Computer science graduates are facing an increasingly difficult job market. Recent data shows a sharp decline in employment outcomes for computer science majors, highlighting the mismatch between what universities teach and what employers now demand. The traditional model of teaching syntax first and hoping students eventually build something useful is no longer working. In this keynote we argue that programming as we knew it is effectively dead. The future lies in AI-First programming, built on the simple loop of try, learn, and grow. Learners try building code with AI assistance, learn by unpacking the generated code and asking AI for detailed explanations, and grow by testing and extending real applications. This loop not only builds confidence but also ensures we grow the generation of AI engineers that companies are desperate to hire.
Speakers
avatar for Stephen Chin

Stephen Chin

VP of Developer Relations, Neo4j
Stephen Chin is VP of Developer Relations at Neo4j, conference chair of the LF AI & Data Foundation, and author of numerous titles including the upcoming GraphRAG: The Definitive Guide for O'Reilly. He has given keynotes and main stage talks at numerous conferences around the world... Read More →
avatar for Cassandra Chin

Cassandra Chin

Java Champion, Book Author, Keynote Speaker, Kids Workshop Instructor, Independent
Cassandra Chin is a keynote speaker, book author, podcast host, children's workshop instructor, and a computer science student. She has been teaching technology kids workshops at international conferences since she was 13 years old and is passionate about helping allow women, minorities... Read More →
Tuesday August 11, 2026 16:35 - 17:05 KST
Magnolia

17:15 KST

GitAIOps: A 4-Layer Architecture for Predictable AI-Assisted Operations - Hoon Jo, Megazone
Tuesday August 11, 2026 17:15 - 17:45 KST
AI agents have no memory between sessions. Every conversation starts from zero. Git becomes the only persistent memory an AI agent can rely on. GitAIOps is the pattern built on this principle: Git is the memory, and a 4-layer architecture defines what goes into that memory.

I applied this to a production migration: 15 Helm releases, Kafka ZooKeeper-to-KRaft, Redis-to-Valkey, full observability stack rebuild. The question: what does Git need to contain so any AI session picks up where the last one left off?

The answer is a 4-layer Git structure, each layer born from a production failure.
Layer 1: Human plans in Git (36 files, 23,854 lines). Too verbose for AI.
Layer 2: Distilled AI context in Git (6 files, 1,254 lines). 19:1 compression as a project state dashboard.
Layer 3: Command Guardrails in Git (117 files). Enforced ordering, no AI-generated commands.
Layer 4: Locked values in Git (30 files). Zero interpretation, reviewed like code.

Every AI action reads from Git, executes, and commits back. The loop is closed.

DEV: 2 weeks → 2 days. PROD: 1 week → 1 day. The session covers the architecture, each layer's failure, and real production artifacts.
Speakers
avatar for Hoon Jo

Hoon Jo

CNCF & AAIF Ambassador | AI & Cloud Native Engineer, Megazone
Hoon Jo is a CNCF Ambassador and Kubestronaut who has spoken at KubeCon North America, Europe, China, and India across multiple years. He is the author of multiple books on Kubernetes and AI-assisted operations. His current work focuses on building operational patterns where AI agents... Read More →
Tuesday August 11, 2026 17:15 - 17:45 KST
Magnolia
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Slides Attached
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -