Roman Zhukov RZ
Wed 14 Oct · 09:30 · Main Stage

Roman Zhukov

Reel · 60 sec ▷ play

— On the schedule —

Nobody Told Maintainers They Were Saving The World. Now Is The Time.

Open source runs everything. But in 2026 the ecosystem that sustains it experiences, perhaps, the biggest simultaneous challenges in its history: maintainer burnout, chronic underfunding, regulatory pressure (e.g, from the EU Cyber Resilience Act), an AI-accelerated vulnerability tsunami, and a flood of AI-generated issues and PRs. In January 2026, the curl shut down their monetary bug bounty program because less than five percent of submissions were real. Elementary permanently bans AI-generated contributions because of quality, ethical and legal risks. To address the social contract crack between maintainers, contributors and users, this talk is about who shows up and what showing up actually looks like at scale. I will walk through Red Hat's decades-long investment in open source security, from being one of the largest corporate contributors for OpenSSL for years to shaping the EU CRA's responsible stewardship model for open source today. As track record alone does not solve today's crisis, I will present three structural responses we are building right now: Lightwell, a five-billion-dollar commitment to automated vulnerability remediation that extends security beyond our own projects to the critical open source libraries the world runs on; Akrites, a Linux Foundation initiative where Red Hat joins 20 organizations to create a shared Security Incident Response Team that acts as a single coordination point and actually invests into helping maintainers; and our Responsible CRA Stewardship approach, that is designed to shield individual contributors from compliance burden while hardening the code everyone depends on. You will leave with a concrete understanding of how responsible stewardship, coordinated response, and sustained engineering support the open source values that brought us here. The call-to-action is far from buying anything, it's a call to arms. Join us in building support for OpenSSL and the broader open source community and learn how you can help maintainers too.

— Compositor's note —

Roman is a cybersecurity expert and leader with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product Security & Privacy for Data Center and AI software at Intel. Roman contributes to global open-source security initiatives and standardization efforts, including the EU Cyber Resilience Act. He is also a university lecturer, startup advisor, and mentor, advocating for practical and responsible cybersecurity.

PlateXXXIX · folio 37 of 91
Guild
DayWed 14 Oct · 09:30 · Main Stage
Track01 — Technical Deep Dive
Format40-min talk
← Back to all twelve plates