Open Community Experience (OCX)

Can open source be secure by design?

38:13 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This talk, presented by Æva Black from Null Point Studio, examines the implications of the Cyber Resilience Act on open source security and sustainability. It details how decades of externalized risk have created systemic security challenges within open source software, highlighting the impact of supply chain attacks and dependency failures. The speaker introduces the concept of the open source steward, a newly defined legal role responsible for supporting open source projects in commercial contexts, and clarifies the steward's obligations compared to maintainers. Additionally, the session discusses proposed security attestation models and their potential to enhance due diligence practices within the software supply chain while promoting a sustainable funding model for open source ecosystems.