Enforcing the OpenSSF Ecosystem With AMPEL - Adolfo García Veytia, Carabiner Systems
Enforcing the OpenSSF Ecosystem With AMPEL - Adolfo García Veytia, Carabiner Systems AMPEL, the Amazing Multipurpose Policy Engine (and L), is the latest open-source project (about) to land in the OpenSSF sandbox. AMPEL is a policy engine designed to be embeddable and easy to use in modern CI/CD environments. It brings together verification of signed in-toto attestations against policies, mapped to security framework controls, enabling projects and organizations to demonstrate compliance with security frameworks. The OpenSSF ecosystem groups tools that produce, manage, and verify security data. AMPEL was created to combine them into a solution that actually protects you. Just name an OpenSSF project, and AMPEL has your back: ✓ Native Sigstore verification ✓ Universal SBOM policies with protobom ✓ SLSA provenance ✓ Built-in OpenVEX support ... and more. These scenarios compose into a coherent solution to comply with common security frameworks, such as the OSPS Security Baseline or the CRA. This is cryptographically probable compliance for everyone! Come and meet AMPEL, its community maintained policy library, and watch our practical examples in this hands-on session that promises a use case for everyone.

How to Set Up a Data Catalog with OpenMetadata!

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

(Podcast) Mastering AI-Driven Code Security with the OpenAI Codex Plugin

Curating Secure Software: The Art of Selecting Safe Dependencies - Kadi McKean, ReversingLabs

Azure Linux 4.0 Is Here: Is Microsoft Finally Embracing Open Source?

JOHN MEARSHEIMER: WHY THIS WAR IS FAR FROM OVER

The End of an Era

Completion-based IO (Alice Ryhl at RustWeek)

Portugal – Demokratische Republik Kongo Highlights | Gruppe K, FIFA WM 2026 | sportstudio

Unfortunately, I Was Right

Inside the Mind of Anthropic CEO Dario Amodei | The Circuit | Extended Interview

Android 17 sucks. So I put Linux on a phone.

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

I Think They Are Lying To You

China Just Build What TSMC Said Was Impossible

310 - Mitchell Hashimoto on Ghostty & His Agentic Coding Workflow

We're 99.9% sure this pattern is true, but no one can prove it

Something is jamming GPS over Europe. Here's what we found

Nicht Krankmelden für den Kanzler? – Lisa Eckhart | Nuhr im Ersten

