<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.1.1. -->
<schedule>
    <generator name="pretalx" version="2026.1.1" />
    <version>1.15</version>
    <conference>
        <title>FOSS Backstage 2026</title>
        <acronym>fossback26</acronym>
        <start>2026-03-16</start>
        <end>2026-03-17</end>
        <days>2</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://program.foss-backstage.de</base_url>
        <logo>https://program.foss-backstage.de/media/fossback26/img/23_FOSSBack_Logo_standard_colour_b0ALw0H.jpg</logo>
        <time_zone_name>Europe/Berlin</time_zone_name>
        
        
        <track name="Governance &amp; Community" slug="6134-governance-community"  color="#fcce57" />
        
        <track name="Economics" slug="6135-economics"  color="#6bd9cc" />
        
        <track name="Legal &amp; Compliance" slug="6136-legal-compliance"  color="#333333" />
        
        <track name="Growing Open Source" slug="6137-growing-open-source"  color="#ffd2d7" />
        
        <track name="Security" slug="6138-security"  color="#98d0e7" />
        
        <track name="Design" slug="6139-design"  color="#e60077" />
        
        <track name="Diversity &amp; Inclusion" slug="6140-diversity-inclusion"  color="#052da5" />
        
    </conference>
    <day index='1' date='2026-03-16' start='2026-03-16T04:00:00+01:00' end='2026-03-17T03:59:00+01:00'>
        <room name='Auditorium' guid='1ddd165f-4197-510d-a2af-9f0953509f9e'>
            <event guid='89fa0370-a6ec-572b-8825-37256008959b' id='85709' code='TYUAXM'>
                <room>Auditorium</room>
                <title>Can Open Source be Secure by Design?</title>
                <subtitle></subtitle>
                <type>Keynote</type>
                <date>2026-03-16T10:05:00+01:00</date>
                <start>10:05</start>
                <duration>00:40</duration>
                <abstract>The tech Industry has relied heavily on Free and Open Source Software for 20 years but under-investing in its security and maintenance has increased global cybersecurity risk. &#198;va Black will reflect on this history and show how regulations could improve security across the ecosystem.</abstract>
                <slug>fossback26-85709-can-open-source-be-secure-by-design</slug>
                <track>Security</track>
                
                <persons>
                    <person id='86775'>&#198;va Black</person>
                </persons>
                <language>en</language>
                <description>For twenty years, the tech industry has externalized more and more risk into the digital commons of free and open source software. Despite the undeniable economic benefits of open source collaboration, by withholding security-essential features and under-investing in communities which maintain that commons, industry has invited disaster.

In response to the sharp rise in global cybersecurity incidents and the role FOSS has played in some of them, some governments mobilized investments and contemplated regulations &#8212; such as SOSSA in the U.S. and the CRA in Europe &#8212; to improve the safety of our now-digital world.

&#198;va Black will reflect on historical inflection points that led to these challenges and share their view of how the Cyber Resilience Act could create a once-in-a-generation opportunity to improve the sustainability of open source communities through Voluntary Security Attestations.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/TYUAXM/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='9b2cdb49-1823-5c79-8b46-66e89cb8d26f' id='83390' code='AY3X7W'>
                <room>Auditorium</room>
                <title>Does FOSS Buy Sovereignty? Participation vs. Ownership</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T11:00:00+01:00</date>
                <start>11:00</start>
                <duration>00:30</duration>
                <abstract>Policy debates often assume FOSS adoption delivers digital sovereignty. But does it? Sovereignty stems not from license freedoms but from technical capacity and community influence. Active participation in FOSS development&#8212;not mere adoption&#8212;determines whether nations achieve independence from proprietary lock-in and foreign control.</abstract>
                <slug>fossback26-83390-does-foss-buy-sovereignty-participation-vs-ownership</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84761'>Mirko Boehm</person>
                </persons>
                <language>en</language>
                <description>Digital sovereignty has become central to EU technology policy, with FOSS frequently positioned as a solution to dependencies on foreign proprietary systems. But simply deploying open source software does not automatically deliver sovereignty.
This talk examines what actually confers digital sovereignty, license freedoms or something more demanding: sustained participation in development communities, institutional knowledge, and capacity to shape technological trajectories. The critical distinction is between passive adoption (downloading and deploying FOSS) and active engagement (contributing code, influencing governance, operating critical infrastructure).
Analysis of different national strategies reveals a counterintuitive finding: copyright ownership matters less than developmental participation. More provocatively, certain forms of international collaboration enhance rather than compromise strategic autonomy, a concept this talk frames as &quot;interdependent autonomy.&quot; Participation in global FOSS communities can strengthen rather than weaken national capabilities.
Key takeaways: what sovereignty requires beyond license compliance, why passive adoption often fails to deliver independence, how different FOSS governance models affect sovereignty outcomes, and whether collaborative innovation can compete with proprietary R&amp;D for strategic capabilities. The implications reshape procurement policy, workforce development strategies, and alliance frameworks for technology cooperation.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/AY3X7W/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d8468a2d-f7e7-56ef-9151-55d4fb3ca1b0' id='83375' code='YXBVP3'>
                <room>Auditorium</room>
                <title>Open Source in Local Governments: Lessons from across the EU</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T11:35:00+01:00</date>
                <start>11:35</start>
                <duration>00:30</duration>
                <abstract>Discover how European local governments successfully collaborate on open source solutions. Based on 5 in-depth case studies including Consul Democracy, Digitransit, and Golemio, learn proven governance models, collaboration archetypes, and actionable strategies for scaling sustainable cross-border digital public services.</abstract>
                <slug>fossback26-83375-open-source-in-local-governments-lessons-from-across-the-eu</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84752'>Nicholas Gates</person>
                </persons>
                <language>en</language>
                <description>As Europe aims for 100% online public services by 2030, local governments face unique challenges in adopting and reusing open source software, particularly when building internal capacity, adapting for the needs of the public sector, working within existing regulations, and collaborating across borders. This talk presents exciting research from a new Open Source Observatory (OSOR) study on open source in local governments, examining five mature European case studies of local government open source collaboration, from Madrid&apos;s Consul Democracy platform used globally to Prague&apos;s Golemio smart city solution.

Participants will discover three critical collaboration archetypes: local governments as adopters, community actors as stewards, and service suppliers as technical enablers. They will learn how cities overcome barriers like conservative procurement practices, limited technical capabilities, and vendor lock-in through innovative governance models and cross-border partnerships. Key takeaways include: proven strategies for designing reusable solutions from day one, funding models that ensure project sustainability, effective roles for local government associations, and recommendations for building capable service supplier ecosystems.

Whether you&apos;re a policymaker, technologist, or open source advocate, you will gain practical insights for creating and sustaining digital infrastructure through collaborative open source development in the public sector.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/YXBVP3/resources/OSOR_FOSS_Backs_cyoMY7m.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/YXBVP3/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='e3ab3b5f-99ba-592e-8b02-915e9be50092' id='82853' code='U9WVEF'>
                <room>Auditorium</room>
                <title>2.5 Years of STA Bug Resilience: how we helped a lot of FOSS</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T12:10:00+01:00</date>
                <start>12:10</start>
                <duration>00:30</duration>
                <abstract>Between major updates for Log4J, substantially increasing test coverage for SystemD, updating hundreds of CVE reports at NIST for Yocto and providing a new infrastructure-as-code solution for PHP, work on FOSS projects for the Sovereign Tech Agency is as varied as it is impactful. This talk recaps the highlights from that past two and half years.</abstract>
                <slug>fossback26-82853-2-5-years-of-sta-bug-resilience-how-we-helped-a-lot-of-foss</slug>
                <track>Security</track>
                
                <persons>
                    <person id='84278'>Jan Lehnardt</person>
                </persons>
                <language>en</language>
                <description>Since October 2023 Neighbourhoodie Software has been the Sovereign Tech Agency&#8217;s partner for the Bug Resilience Program and has helped improve a large number of high-profile FOSS projects.

For FOSS maintainers, this talk covers how the program works, how you can apply and what you can expect from it.

For the generally curious, this talk gives a fascinating insight into the variety of the FOSS landscape, what projects of different sizes, ages and importances struggle with, and how the team at Neighbourhoodie managed to make substantial contributions. The insights begin with the peculiarities of how certain projects organise their project communication, what they think is important to address (versus what the world might think is important) and we&#8217;ll cover the gratitude project maintainers send us after a job well done.

This talk also covers strategies for how to become a valuable contributor in projects of high complexity and impact in just a couple of days. Communication and honesty are obviously key, but some skill is required and this talk will help you get up to speed, should you want to join and help a project.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/U9WVEF/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0e4f0ed2-7fd6-5097-817c-69361f3d5c2a' id='83277' code='8HNECT'>
                <room>Auditorium</room>
                <title>Building the Open Alternative: DPGs for Digital Sovereignty</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T14:00:00+01:00</date>
                <start>14:00</start>
                <duration>00:30</duration>
                <abstract>Digital sovereignty is becoming a key objective of societies and nations. Learn how Digital Public Goods (DPG) like Mastodon can build a decentralised internet and challenge big tech. A joint talk by DPGA &amp; Mastodon&#8212;we&apos;ll unpack the concept, analyse EU policy, and offer concrete strategies for a sovereign digital future.</abstract>
                <slug>fossback26-83277-building-the-open-alternative-dpgs-for-digital-sovereignty</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84714'>Andy Piper</person>
                </persons>
                <language>en</language>
                <description>Digital sovereignty&#8212;the ability for nations, organisations, and individuals to control their own digital future&#8212;is one of the key policy priorities of our time. This joint talk, shared between a representative from the Digital Public Goods Alliance (DPGA) and a team member from Mastodon, will explain how Digital Public Goods (DPGs) are a key building block for achieving greater digital sovereignty in the wake of geopolitical insecurity. 

We will start by unpacking the term &quot;digital sovereignty&quot; and the role open source technologies and digital public goods play in it. We will then discuss the strengths and weaknesses of core EU policies that support the open source ecosystem, mandating interoperability and data portability as key measures to level the playing field and provide opportunities for open alternative solutions. 

We will use Mastodon as a prime example of a globally recognised, federated DPG that challenges entrenched market powers, discussing practical pathways for seizing the opportunities EU policies provide. We aim to move beyond philosophical debates to offer concrete strategies for leveraging FOSS for the public good, helping to build and maintain a decentralised and democratically controlled internet infrastructure with sovereignty at its heart.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/8HNECT/resources/BuildingTheOpen_rn4aPXH.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/8HNECT/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='81f1bd01-bf10-5671-aea9-532a19a6efb9' id='83376' code='DBGRPB'>
                <room>Auditorium</room>
                <title>How the city of Munich measures digital sovereignty</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T14:35:00+01:00</date>
                <start>14:35</start>
                <duration>00:30</duration>
                <abstract>Due to the changed global political situation, digital sovereignty is a priority goal for every organization. The city of Munich has developed a simple method for measuring digital sovereignty and has derived measures based on this. In our talk, we will present the measurement method, planned measures, and how FOSS can help achieve this goal.</abstract>
                <slug>fossback26-83376-how-the-city-of-munich-measures-digital-sovereignty</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='88683'>Jutta Kreyss</person>
                </persons>
                <language>en</language>
                <description>With 43,000 employees, the City of Munich administration is the largest employer in the city and has its own comprehensive IT provider. With our own data center, we have the opportunity to achieve a high degree of digital sovereignty. In order to systematically increase our digital sovereignty, we have developed a measurement method that evaluates various criteria. In our talk, we will show how the measurement method is used and what measures have been derived from it. We will place a special focus on measures that promote the use of FOSS.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/DBGRPB/resources/CityOfMunichSor_9yNlSps.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/DBGRPB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2c45d256-8879-5147-973e-5db0263fe2fa' id='82876' code='HUYQVA'>
                <room>Auditorium</room>
                <title>A Frictionless Inner Source Journey</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T15:30:00+01:00</date>
                <start>15:30</start>
                <duration>00:30</duration>
                <abstract>Inner Source success hinges on easy contributions. However, complex frameworks can be a barrier. We simplified our process by removing bureaucratic hurdles, automating compliance, and simplifying project involvement. Discover how to create a frictionless Inner Source experience and unlock your company&apos;s collaborative potential!</abstract>
                <slug>fossback26-82876-a-frictionless-inner-source-journey</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84258'>Dr. Wolfgang Gehring</person>
                </persons>
                <language>en</language>
                <description>For Inner Source to thrive and gain contributors, we need to make the experience as frictionless as possible. Often, we have built large frameworks around Inner Source with the intention of maximizing safety and governance, but these frameworks can inadvertently create unintended obstacles for potential contributors. 

Let us share with you how we can address this challenge. We assessed the full process for contributing to Inner Source within our company, including all requirements, necessary actions, and governance regulations. We analyzed and measured where people spend time in the process, and then came up with suggestions for cutting the red tape and also for automating unloved compliance topics. 

Finally, for a smooth Inner Source journey, also from an individual project perspective, we need to make it as easy as possible to contribute. We&#8217;ll share some examples and suggestions here which can serve as a model for achieving this.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/HUYQVA/resources/Wolfgang_Gehrin_6q4ry5N.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/HUYQVA/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='aecacf51-9562-580d-91f9-9d9ccd4c0275' id='83205' code='LMFJLF'>
                <room>Auditorium</room>
                <title>Is InnerSource Commons good for open source?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T16:05:00+01:00</date>
                <start>16:05</start>
                <duration>00:30</duration>
                <abstract>The InnerSource commons promotes the adoption of open source practices to accelerate development within a company&apos;s culture. It&apos;s also said that it prepares the ground for those companies to begin contributing and releasing open source software... but can we prove it?</abstract>
                <slug>fossback26-83205-is-innersource-commons-good-for-open-source</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84613'>Benjamin Nickolls</person><person id='84614'>Andrew Nesbitt</person>
                </persons>
                <language>en</language>
                <description>Using data from hundreds of millions of open source repositories provided by ecosyste.ms we seek to answer the question: is The InnerSource Commons good for open source? 

We look at data from 800 member companies to answer what might seem like a simple question, in the process unpacking what it means to support, contribute, and maintain open source software. What a &apos;healthy&apos; open source project looks like, and where and how we can identify and support important projects that need our help.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/LMFJLF/resources/Andrew_Nesbitt__ADm6dZd.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/LMFJLF/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='b538fde8-85da-522a-8019-72fc0aa49d1e' id='83394' code='99J3CV'>
                <room>Auditorium</room>
                <title>From Tires to Code: Building Michelin&apos;s OSPO</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T16:40:00+01:00</date>
                <start>16:40</start>
                <duration>00:30</duration>
                <abstract>Michelin, a 136-year-old industrial giant, is building its open source culture. This talk is a feedback from our OSPO, detailing our strategy, governance, and change management programs. We&apos;ll share our progress and achievements, our key lessons, and the significant challenges still ahead on our journey.</abstract>
                <slug>fossback26-83394-from-tires-to-code-building-michelin-s-ospo</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84767'>Florent Zara</person><person id='88684'>Julien Millau</person>
                </persons>
                <language>en</language>
                <description>Launching an OSPO in a global, non-tech-native corporation presents unique cultural, legal, and organizational hurdles. This session provides a practical feedback on how Michelin built and now operates its OSPO.

We will walk through the entire journey, covering:

* The historical context and business strategy that drove the need for a formal OSPO.  
* The practical steps of establishing a strong governance model and the OSPO&apos;s structure  
* A deep dive into our multi-faceted program for cultural change. This is now the core of our strategy and includes:  
  * Company-wide training modules (which we are now in the process of open sourcing).  
  * A gamified badging system to incentivise learning and contribution.  
  * The creation and management of an OSS Champions community to scale our efforts.  
* Our approach to external communication   
* The tools we use.  
* And finally, the road ahead us: the significant challenges that remain on our journey.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/99J3CV/resources/20260316_From_T_zwnxVUa.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/99J3CV/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='9bbb0967-ecd6-5d9c-9eff-4850384dba2f' id='94775' code='CL33TG'>
                <room>Auditorium</room>
                <title>Shifting Left on Human Rights?</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:20:00+01:00</date>
                <start>17:20</start>
                <duration>00:05</duration>
                <abstract>The W3C integrates accessibility, security, and ethics into web standards. Inspired by UN human rights recommendations, this talk explores the W3C&#8217;s review process, its vital importance, and how these principles can be applied to other domains.</abstract>
                <slug>fossback26-94775-shifting-left-on-human-rights</slug>
                <track></track>
                
                <persons>
                    <person id='94577'>Daniel Appelquist</person>
                </persons>
                <language>en</language>
                <description>In Open Standards and specifically in W3C, we have a culture and a process of wide review to ensure that specifications that
move through our process are evaluated for things like accessibility, internationalisation, privacy and security. We also have
introduced ethical considerations. Meanwhile the UN Office of the Hight Commissioner of Human Rights has released a report last
year about how Open Standards development organisations can and should be incorporating human rights into their process. This
talk is a speed run through what we&apos;re doing in this space in W3C, why it matters - and hopefully how it could be applied to other
domains.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/CL33TG/resources/01_Shift-left_m0naXva.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/CL33TG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c7725e48-c368-53a7-847f-0d6fb929f8b2' id='94776' code='HF89EC'>
                <room>Auditorium</room>
                <title>Using content from Wikidata in your apps</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:25:00+01:00</date>
                <start>17:25</start>
                <duration>00:05</duration>
                <abstract>Wikidata is a CC 0 licensed, semantic knowledge base of linked data. This talk argues for its use in apps, highlighting its diverse data types and strengths. It concludes with a showcase of existing applications to demonstrate Wikidata&#8217;s practical potential.</abstract>
                <slug>fossback26-94776-using-content-from-wikidata-in-your-apps</slug>
                <track></track>
                
                <persons>
                    <person id='84187'>Jan Ainali</person>
                </persons>
                <language>en</language>
                <description>Wikidata is an openly licensed (CC 0) knowledge base containing a wide array of subjects. Thanks to the semantic model,
subjects can be linked to each other and it can be queried in various ways. This talk is an argument of why you should use
content from Wikidata in your apps. The talk will show what kind of data is available, and what it is particularly good at. It&apos;ll end
with a mosaic / medley / showcase of a few apps already using Wikidata.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/HF89EC/resources/Using_Wikidata__5MDoVJs.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/HF89EC/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='20258474-3de8-53dc-8562-ca0b9224a6dd' id='94778' code='CESJWE'>
                <room>Auditorium</room>
                <title>Connecting Open Source Projects with Public Institutions</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:30:00+01:00</date>
                <start>17:30</start>
                <duration>00:05</duration>
                <abstract>Public institutions increasingly rely on open-source software but lack direct ties to its maintainers. This talk proposes institutionalizing exchange channels to share roadmaps and report bugs. By bridging this gap, both developers and the public sector can better align their goals and strengthen critical digital infrastructure.</abstract>
                <slug>fossback26-94778-connecting-open-source-projects-with-public-institutions</slug>
                <track></track>
                
                <persons>
                    <person id='94579'>Oliver Drotbohm</person>
                </persons>
                <language>en</language>
                <description>Public institutions across Germany and Europe are increasingly building administrative software on open source libraries. Yet the
open source projects underpinning this infrastructure often lack visibility into who is using their software, what challenges those
users encounter, and which features would be most valuable to the public sector.
I propose to institutionalize the exchange between open source projects and public institutions for mutual benefit &#8212; establishing
direct interaction channels to discuss challenges, communicate roadmaps, report bugs, and broadly strengthen the relationship
between maintainers and their public-sector users.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/CESJWE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c227e14e-60f2-547e-addc-7f629f5fce0f' id='94780' code='XRCR9V'>
                <room>Auditorium</room>
                <title>Training-as-Code: Scaling Open Source Literacy</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:35:00+01:00</date>
                <start>17:35</start>
                <duration>00:05</duration>
                <abstract>Shared educational efforts need more than static files; they require a scalable, community-driven approach. This talk introduces Eclipse OSILK, a &quot;Training-as-Code&quot; project using AsciiDoc for modular, maintainable training. It enables organizations to tailor content easily while keeping it as evergreen as the software itself.</abstract>
                <slug>fossback26-94780-training-as-code-scaling-open-source-literacy</slug>
                <track></track>
                
                <persons>
                    <person id='84767'>Florent Zara</person>
                </persons>
                <language>en</language>
                <description>Mutualising educational efforts between organisations requires more than just a few PDF/PPT/&#8230; slide decks or markdown files
shared on a Git repo. It requires a scalable, maintainable, and community-driven approach to education.
In this talk, we introduce Eclipse OSILK (Open Source &amp; InnerSource Learning Kit), a brand-new project designed to provide high-
quality, modular training materials. We will explore the project&apos;s unique &quot;Training-as-Code&quot; philosophy, which leverage AsciiDoc
and version control to ensure that training materials remain as evergreen and collaborative as the software they describe.
Organisation will be able to easily tailored it to their needs.
With this lightning talk, we want to bring on more companies on board!</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/XRCR9V/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='90323ae1-54b2-5f7f-8775-9b264ae5d64f' id='94782' code='XHEVEB'>
                <room>Auditorium</room>
                <title>The next xz attack</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:40:00+01:00</date>
                <start>17:40</start>
                <duration>00:05</duration>
                <abstract>Gemini hat gesagt
The 2021&#8211;2024 xz backdoor attack exploited social engineering to target critical SSH infrastructure. This talk warns that, fueled by LLMs, similar attacks will rise, and the traditional profile of &quot;undermaintained&quot; projects being the only targets no longer applies. Security models must adapt to these sophisticated new threats.</abstract>
                <slug>fossback26-94782-the-next-xz-attack</slug>
                <track></track>
                
                <persons>
                    <person id='94580'>Daphne Preston-Kendal</person>
                </persons>
                <language>en</language>
                <description>Between 2021 and 2024 a successful social engineering attack inserted a backdoor into the xz compression library which, due to
xz&#8217;s use in the SSH protocol for connecting to remote servers securely, could have allowed the attacker access to practically any
server running an open source OS in the world. This talk will suggest that, in the age of LLMs, this is not the last attack of this kind
we will see, and that the classical vulnerability profile of an undermaintained project, which was seen in the case of xz, may not
necessarily apply.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/XHEVEB/resources/next-xz-attack_ztF1iz7.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/XHEVEB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='b7d18775-783b-5bc9-9306-37ba3efd7797' id='94783' code='Q37SN7'>
                <room>Auditorium</room>
                <title>Should I do my homework with AI - with parallels to FOSS</title>
                <subtitle></subtitle>
                <type>Lightning Talk</type>
                <date>2026-03-16T17:45:00+01:00</date>
                <start>17:45</start>
                <duration>00:05</duration>
                <abstract>We&apos;ll host a five minute mini debate on stage on the exciting question of whether or not you should do your homework with the help
of AI. The debate will be supported by FOSS maintainers, former and current students.
We&apos;ll stay strictly within the humorous topic, parallels to FOSS development are entirely incidental and not by intention at all ;)</abstract>
                <slug>fossback26-94783-should-i-do-my-homework-with-ai-with-parallels-to-foss</slug>
                <track></track>
                
                <persons>
                    <person id='94581'>Isabel Drost-Fromm</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/Q37SN7/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d3228d15-a6bd-565f-8638-a73f262405f5' id='88191' code='TD9BPR'>
                <room>Auditorium</room>
                <title>Get-Together</title>
                <subtitle></subtitle>
                <type>Off Stage</type>
                <date>2026-03-16T18:10:00+01:00</date>
                <start>18:10</start>
                <duration>01:30</duration>
                <abstract>Join us for a drink and a chat at our Get Together directly after the conference!</abstract>
                <slug>fossback26-88191-get-together</slug>
                <track></track>
                
                <persons>
                    
                </persons>
                <language>en</language>
                <description>What better way to end the first day of FOSS Backstage than with a Get Together?

Take the opportunity to meet old and new friends or maybe the person to collaborate with on your next project in a relaxed atmosphere.

If your Organization want to support us in offering food and drinks at the get together please contact partner@foss-backstage.de or learn more [here](https://26.foss-backstage.de/become-a-partner/).</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/TD9BPR/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='11508992-655d-5e13-bc07-deece56ad487' id='83438' code='TLYQRN'>
                <room>Auditorium</room>
                <title>Tour: c-base a space station under Berlin</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-16T19:40:00+01:00</date>
                <start>19:40</start>
                <duration>01:00</duration>
                <abstract>Do you dare to visit a space-station under Berlin?
Do you want to visit Germanys oldest Hackerspace?
Do you want to enjoy decent food and a mate with fellow FOSS Backstage attendes?

The join us!

We will send an expedition team from FOSS Backstage to explore c-base and meet the local population.</abstract>
                <slug>fossback26-83438-tour-c-base-a-space-station-under-berlin</slug>
                <track>Diversity &amp; Inclusion</track>
                
                <persons>
                    <person id='84793'>Gregor &quot;Little Detritus&quot; Bransky</person>
                </persons>
                <language>en</language>
                <description>10.000 years into the future humanity will venture into the wide realm of space. In order to terraform planets other planets c-base was constructed as an orbital multivoltine space-station. Due to a Flip-Flop of the Asimov-Constant the cybernetic quicksilver reactor failed. Instead of materializing in the orbit of Gliese 12b c-base was thrown back in the space time continuum by 4.5 billion years and crashed on the surface of earth and slowly sank into the Brandenburg sand.

That or something like that is what it&#180;s crew members claim to be the origin story of c-base. Founded in 1995 it is Germanys and probably the world oldest hackerspace run by the NGO c-base e.V.

Following it&#180;s creed &quot;be future compatible!&quot; c-base understands itself as a space that allows nerds, geeks, hackers, dreamers and data travelers to gather, converse and discuss how to think and act to make a better future possible. Whatever that may be.

In this spirit it not only hosted Lounge of the Chaos Communication Congress when it was held in Berlin. Both the &quot;F&#246;rderverein f&#252;r freie Netzwerke e.V.&quot; (2003) german first Freifunk chapter as well as the german Pirate Party (2006) were founded at c-base and the very first BerlinBuzzwords (2009) took place there.

To end the first evening of the FOSS Backstage, we offer a tour of c-base. Followed the opportunity to enjoy ending the evening at one of it&#180;s recreational modules with a cold beverage at Sprees waterside with a view of c-base center axis know as the Berliner Fernsehturm to the uninitiated.

c-base can be found at Rungestra&#223;e 20 close to Jannowitzbr&#252;cke.

For food orders: https://cryptpad.fr/sheet/#/2/sheet/edit/9+Q5p+q9-UV0r5J8I60HkZLc/</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/TLYQRN/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='bUm Box' guid='deb473ee-a453-5811-bbc3-605d58e50a3e'>
            <event guid='945ee8c2-71be-564b-bc5b-bafeabcb6eaa' id='83227' code='EUKCJZ'>
                <room>bUm Box</room>
                <title>Success Stories in Open Source: Security Audits with OSTIF</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T11:00:00+01:00</date>
                <start>11:00</start>
                <duration>00:30</duration>
                <abstract>Improved security in open source is more than a theoretical goal but a plausible reality as shown by nonprofit Open Source Technology Improvement Fund, Inc. Following a best practice of independent code review with a process specifically tailored to open source projects and communities, OSTIF is turning funds into positive security outcomes.</abstract>
                <slug>fossback26-83227-success-stories-in-open-source-security-audits-with-ostif</slug>
                <track>Security</track>
                
                <persons>
                    <person id='84631'>Amir Montazery</person>
                </persons>
                <language>en</language>
                <description>The speaker will talk about the importance of security audits and a process tailored to open source communities, and highlight numerous success stories in improving the security posture of open source projects. Examples include the audit of git, kubernetes, ruby on rails, and php-src. The topic is relevant to the audience because the evidence presented in the talk suggests that a real implementable solution to solve the security and technical debt of software projects is tenable. The main takeaways are as follows: (a)Security audits are an effective tool for helping improve the security posture of projects (b)Projects of all sizes, maturity levels, and complexities have benefited from additional security audit work and (c) OSTIF, as an independent nonprofit, is facilitating and executing security audits for critical open source projects at a high level of effectiveness. While many solutions to the security problems of open source are theoretical and require considerable effort, OSTIF has honed in on a process to help open source projects en masse with a well established best practice: independent expert security review.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/EUKCJZ/resources/Success_Stories_uq7V4Kq.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/EUKCJZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='3f3d1ccc-3f06-5b99-adad-0865a396505c' id='83281' code='Z7XHQ7'>
                <room>bUm Box</room>
                <title>Identifying and Addressing Usability Vulnerabilities</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T11:35:00+01:00</date>
                <start>11:35</start>
                <duration>00:30</duration>
                <abstract>Security can fail even when code is correct. Drawing on work with SecureDrop, Qubes OS, and Mailvelope, this talk defines &#8220;usability vulnerabilities,&#8221; design flaws that cause unsafe behavior, and shows how open-source teams can detect and address them before release.</abstract>
                <slug>fossback26-83281-identifying-and-addressing-usability-vulnerabilities</slug>
                <track>Security</track>
                
                <persons>
                    <person id='84676'>Elio Qoshi</person><person id='84717'>Anxhela Maloku (Angie)</person>
                </persons>
                <language>en</language>
                <description>Even well-engineered security tools can expose users to risk if design choices make safe actions unclear or burdensome. This talk examines how usability directly shapes security, based on Ura Design&#8217;s audits and field studies for SecureDrop, Qubes OS, and Mailvelope.

We define a usability vulnerability as a design flaw that predictably leads users to unsafe behavior, despite correct technical implementation. Examples include misleading encryption states, ambiguous trust cues, and compartmentalization patterns that break user mental models.

The session introduces a repeatable method for identifying and documenting such vulnerabilities within existing security review cycles. Attendees, including maintainers, designers, and security reviewers, will learn how to integrate usability findings into threat models, triage design issues with the same rigor as code CVEs, and prevent security regressions before they reach production.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/Z7XHQ7/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='b931678c-7885-5a3b-9663-73df1886ddca' id='81737' code='JYA8J9'>
                <room>bUm Box</room>
                <title>Beyond the license: measuring real openness in open source</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T12:10:00+01:00</date>
                <start>12:10</start>
                <duration>00:30</duration>
                <abstract>Open source licenses like GPL or MIT matter, but ecosystem is what truly defines how open and sustainable a project is. Open source isn&apos;t always as open as it seems! There are many tactics beyond licensing to lock you in - and copyleft isn&apos;t always better than permissive, or vice-versa.</abstract>
                <slug>fossback26-81737-beyond-the-license-measuring-real-openness-in-open-source</slug>
                <track>Legal &amp; Compliance</track>
                
                <persons>
                    <person id='83241'>Jos Poortvliet</person>
                </persons>
                <language>en</language>
                <description>Open source licenses like GPL or MIT matter, but aren&apos;t the whole story. An open project is often rather defined by its ecosystem: transparency, contribution access, buildability, and governance. In this talk, we&#8217;ll explore how projects often lean on their license as a proxy for openness, even while locking in features, obscuring build processes, or limiting community agency. I&apos;d like to introduce the &#8220;Is It Really FOSS?&#8221; initiative, and have a look at how legal license choices intersect with reality. Let&apos;s look at lock-in tactics beyond licensing and how to build and steward genuinely open projects that can still be sustainable.

Why it&#8217;s relevant:
	&#8226;	Legal professionals and OSPOs will gain insight into how licensing interacts with project structure and governance.
	&#8226;	Entrepreneurs and contributors will learn how to evaluate and encourage true openness&#8212;not just in words, but in processes.
	&#8226;	It helps you look beyond pure licensing to ecosystem trust and sustainability.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/JYA8J9/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='97a89547-f565-5c84-8b53-e6509c2f9c66' id='83400' code='7D3LYX'>
                <room>bUm Box</room>
                <title>How open source companies win</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T14:00:00+01:00</date>
                <start>14:00</start>
                <duration>00:30</duration>
                <abstract>We talk about license changes and risk management for open source companies all the time, but what about how open source companies can use their open source project as a competitive advantage to win in their market? That&apos;s what this talk is about.</abstract>
                <slug>fossback26-83400-how-open-source-companies-win</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84769'>Emily Omier</person>
                </persons>
                <language>en</language>
                <description>When an open source companies abandons their open source license, it&apos;s rarely because they are horrible people and more often because they&apos;ve failed to use open source to their advantage. 

In this talk, I&apos;ll draw on concrete examples from five years of The Business of Open Source, plus my experience as a consultant, to talk about ways that an open source project can give a company an advantage in terms of product development, marketing, sales enablement, internal alignment and more. The goal of this talk is to ultimately prevent more companies from abandoning open source by giving them a concrete roadmap for how to not just mitigate risk but really leverage their open source project to accelerate their business growth over the long term.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/7D3LYX/resources/How_Open_Source_j4agBmY.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/7D3LYX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='f93e8a78-db70-5cdf-adc8-b827afcfa696' id='82176' code='H9QXS9'>
                <room>bUm Box</room>
                <title>AI-Generated Code: Legal Risks and How to Reduce Them</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T14:35:00+01:00</date>
                <start>14:35</start>
                <duration>00:30</duration>
                <abstract>Anyone who still puts AI-generated code into circulation today has conditional intent to infringe the law &#8211; how to limit or at least defer the risk.</abstract>
                <slug>fossback26-82176-ai-generated-code-legal-risks-and-how-to-reduce-them</slug>
                <track>Legal &amp; Compliance</track>
                
                <persons>
                    <person id='83598'>Dr. Andreas Kotulla</person><person id='87310'>Chan-jo Jun</person>
                </persons>
                <language>en</language>
                <description>AI tools such as GitHub Copilot are not creative geniuses &#8211; they copy! And they do so more frequently and more demonstrably than many people believe. Anyone who incorporates AI-generated code into their software today is often already acting with conditional intent &#8211; and making themselves vulnerable to claims for damages, injunctions, and even criminal consequences.
We present current developments, figures on the frequency of plagiarism, and other prominent cases, shed light on the legal situation, and explain why companies urgently need to protect themselves. We provide clear answers to burning questions:
1. Why does AI code become a liability risk?
2. How can software manufacturers and purchasers still protect themselves?
3. What technical and legal measures can prevent a ticking time bomb in your own product?
 Anyone who uses AI code carelessly in the future will be left to deal with the damage. We show you how to save yourself&#8212;before it&apos;s too late.
Speakers:
Chan-jo Jun and Dr. Andreas Kotulla</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/H9QXS9/resources/Andreas_Kotulla_Oc7ik2K.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/H9QXS9/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='f420b1c7-1f0c-5865-a0bd-d2c49a9fdbc6' id='83336' code='GEVCRG'>
                <room>bUm Box</room>
                <title>ORT Server: An open source platform to automate CRA checks</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T15:30:00+01:00</date>
                <start>15:30</start>
                <duration>00:30</duration>
                <abstract>The ORT Server is a platform building on the renown OSS Review Toolkit to automate software compliance checks in a scalable and enterprise-ready way. This talk gives an overview of how to use the ORT Server to deal with obligations of the Cyber Resilience Act (CRA) specifically.</abstract>
                <slug>fossback26-83336-ort-server-an-open-source-platform-to-automate-cra-checks</slug>
                <track>Legal &amp; Compliance</track>
                
                <persons>
                    <person id='83776'>Sebastian Schuberth</person><person id='84758'>Martin Nonnenmacher</person>
                </persons>
                <language>en</language>
                <description>It is challenging esp. for small to medium enterprises (SMEs) to understand and deal with the obligations from the Cyber Resilience Act (CRA). While commercial solutions exist, these usually come at a high cost and the risk of a vendor lock-in. This talk provides an overview of how the open source ORT Server platform can help here.

The talk will start with a bit of history of the OSS Review Toolkit and ORT Server projects, how they relate to each other, who the target audiences are, and highlight some technical differences between the two solutions.

While the ORT Server also has a REST API, the talk will then focus on using its dedicated UI for making the complex compliance topic and legal workflows more accessible to less technical users. At a concrete example project, the talk will guide through how to deal with vulnerabilities and other policy rule violations found in a way that fulfills CRA requirements.

Finally, an outlook will be given over the upcoming and planned features for ORT Server, extending it a general platform to automate software compliance checks including and beyond other regulations like NIS2 and DORA.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/GEVCRG/resources/ORT_Server_-_An_9FFUB8X.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/GEVCRG/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='ea145903-dc6c-5014-95fa-e592598cfa24' id='83442' code='BBM8MF'>
                <room>bUm Box</room>
                <title>Curating Power: FOSS in the Service of National Interests</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T16:05:00+01:00</date>
                <start>16:05</start>
                <duration>00:30</duration>
                <abstract>Around the world, governments are building and exporting their own &#8220;open&#8221; technology stacks &#8212; from India Stack to the emerging Deutschland Stack &#8212; blending open-source ideals with national strategy. This talk dives into how states are curating open technologies to reflect political philosophies, advance digital sovereignty, and shape global norm.</abstract>
                <slug>fossback26-83442-curating-power-foss-in-the-service-of-national-interests</slug>
                <track>Legal &amp; Compliance</track>
                
                <persons>
                    <person id='84795'>Cassie Jiun Seo</person>
                </persons>
                <language>en</language>
                <description>Open source has long been celebrated as a global commons &#8212; a space where collaboration transcends borders. But what happens when states start curating their own open stacks? From India Stack to the emerging &#8220;Deutschland Stack,&#8221; governments are assembling and exporting open-source components as part of their digital public infrastructure strategies. These stacks aren&#8217;t just technical blueprints &#8212; they&#8217;re instruments of digital sovereignty, industrial policy, and geopolitical influence.

This talk explores how open source has become a site of stack diplomacy: where nations intentionally assemble, govern, and export open technologies to shape global standards and alliances. Drawing on examples from India, China, and the EU, we&#8217;ll unpack how &#8220;stack curation&#8221; works &#8212; how the choice of APIs, identity frameworks, or governance models can reflect national philosophies, and how this transforms open infrastructure into soft (and sometimes hard) power.

We&#8217;ll discuss what this means for open source communities:

How do we navigate the line between openness and national interest?

Can open collaboration coexist with state-led curation?

And what responsibilities do open source maintainers have in this new landscape?

By the end, participants will have a clearer understanding of how open stacks are reshaping global cooperation &#8212; and how the open source community can respond to ensure openness remains a principle, not just a branding tool.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/BBM8MF/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='a110b2c4-c54c-5a09-95af-f3dff96d27fb' id='83183' code='NHYLVP'>
                <room>bUm Box</room>
                <title>FLOSS Sustainability: Lessons from a Funding Crisis</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-16T16:40:00+01:00</date>
                <start>16:40</start>
                <duration>00:30</duration>
                <abstract>Decidim, once reliant on Barcelona&#8217;s funding, faced a 2022 crisis that spurred a Sustainability Plan to diversify income. Three years on, we share strategies, challenges, and lessons in securing funding from public, private, and philanthropic sources for FLOSS project sustainability.</abstract>
                <slug>fossback26-83183-floss-sustainability-lessons-from-a-funding-crisis</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84588'>Nil Homedes</person>
                </persons>
                <language>en</language>
                <description>Since its inception, Decidim has relied primarily on funding from the city of Barcelona, creating a dependency on this public organization. In 2022, following a funding crisis that nearly jeopardized the project, we developed a Sustainability Plan aimed at diversifying funding sources and reducing our dependence on a single funder.

Three years after implementing the plan, we have made significant progress toward our goal.

This session will reflect on our approach and key learnings. We will explain how we designed this plan, the challenges for sustainability that a FLOSS project faces, the learnings we have made during the process and the main actions we have taken

We will delve into the different strategies we have designed to attract new funders, especially from the private and philanthropic sector, as well as the challenges we face when it comes to receiving funding from public agencies. Finally, we will evaluate the successes and failures of this plan.

This is an ideal talk if you are interested in knowing the challenges that FLOSS projects face when seeking funding, want to learn which are the best strategies to diversify your sources of income and ensure a sustainable growth of your project.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/NHYLVP/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Wintergarten' guid='888139d6-e46d-5d53-b8d2-844aa948a342'>
            <event guid='079580b7-079b-51ed-abd4-15cad59133cc' id='83148' code='BUEQLX'>
                <room>Wintergarten</room>
                <title>Open-Source Stewards Under the CRA: NPO Pitfalls</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-16T11:35:00+01:00</date>
                <start>11:35</start>
                <duration>01:00</duration>
                <abstract>The CRA&#8217;s Open-Source Software Steward (OSSS) status offers legal recognition and hidden traps for non-profits and volunteer communities. This talk unpacks benefits, duties, liability, and tax effects, helping NPOs use the status safely and avoid accidental burdens.</abstract>
                <slug>fossback26-83148-open-source-stewards-under-the-cra-npo-pitfalls</slug>
                <track>Legal &amp; Compliance</track>
                
                <persons>
                    <person id='84548'>Maximilian Kroker</person>
                </persons>
                <language>en</language>
                <description>The EU Cyber Resilience Act (CRA) introduces the Open-Source Software Steward (OSSS) role &#8212; a novel legal construct acknowledging entities that systematically support open-source development. While it promises lighter duties than full &#8220;manufacturers,&#8221; the OSSS label can create unexpected exposure for foundations, associations (e.V.s) and volunteer organizations.
This session focuses exclusively on non-commercial actors &#8212; not on businesses seeking OSSS qualification &#8212; and explores the pitfalls of leveraging the status:
    &#8226; Benefits of OSSS recognition for NPOs: legitimacy, funding leverage, and security-governance credibility.
    &#8226; Problems &amp; Obligations: Article 24 CRA obligations (security policy, vulnerability handling, authority cooperation).
    &#8226; Achieving / Avoiding OSSS classification.
    &#8226; Liability effects: how far the penalty exception in Art. 64 para. 10 CRA could extend to civil liability.
    &#8226; Tax status implications: narrative conflicts between &#8220;intended for commercial activities&#8221; and non-profit status (Gemeinn&#252;tzigkeit); mitigation through legal operations and desirable tax legislation.
    &#8226; Other legal angles: antitrust boundaries and GDPR responsibilities.
    &#8226; &#8220;OSSS as a Service&#8221;: outsourcing as an option for every NPO? And what to keep in mind when signing and executing such an agreement?
    &#8226; Case Studies:
        &#9702; A German Fediverse gGmbH with no non-profit status and it&#8217;s U.S. 501(c)(3) counterpart
        &#9702; A Belgian Private Foundation
        &#9702; A German Association with non-profit status

&lt;b&gt;This session is an interactive session and therefore not recorded.&lt;/b&gt;</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/BUEQLX/resources/Open-Source_Ste_5IgUOdn.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/BUEQLX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='e654f4b8-4321-5a5f-959e-17e71e1f287b' id='83751' code='SANATD'>
                <room>Wintergarten</room>
                <title>Co-Creating RIECS with Open Source Builders</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-16T14:00:00+01:00</date>
                <start>14:00</start>
                <duration>01:00</duration>
                <abstract>Open source projects already power citizen science &#8212; from mapping air quality to tracking food data. This RIECS-Concept workshop invites developers and community leads to share stories and map what support, tools, and governance are needed to build sustainable, open, and trusted citizen science infrastructures.</abstract>
                <slug>fossback26-83751-co-creating-riecs-with-open-source-builders</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='85736'>Kai-Ti Wu</person><person id='92671'>Franziska Stressmann</person>
                </persons>
                <language>en</language>
                <description>Open source builders are at the heart of many citizen science initiatives &#8212; creating platforms, tools, and data systems that enable communities to participate in real research. Yet, these efforts often face similar challenges: maintaining software, ensuring data quality, and sustaining collaboration.

This 60-minute RIECS&#185;-Concept workshop brings together developers, maintainers, and project organizers to share experiences and identify what kinds of technical services, governance models, and community support are most needed.

The insights gathered will inform the concept design of a European research infrastructure for citizen science &#8212; connecting open source innovation with participatory research and long-term sustainability.

Learn more about the RIECS-Concept: &lt;a href=&quot;https://concept.riecs.eu/&quot; target=&quot;_blank&quot;&gt;Project Website&lt;/a&gt; | &lt;a href=&quot;https://mastodon.social/@riecs_concept/&quot; target=&quot;_blank&quot;&gt;Mastodon&lt;/a&gt;

&#185; Research Infrastructure for Excellence in Citizen Science

&lt;b&gt;This session is an interactive session and therefore not recorded.&lt;/b&gt;</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/SANATD/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='5fda11e2-ac1b-5050-be7a-5abae348cc9c' id='83162' code='TRCEGN'>
                <room>Wintergarten</room>
                <title>Stable software needs stable funding &#8212; Mapping workshop</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-16T15:30:00+01:00</date>
                <start>15:30</start>
                <duration>01:00</duration>
                <abstract>This workshop explores funding and resource models for sustaining FOSS projects. We look at grants, donations, sales, licenses, corporate and student contributions, and more &#8212; evaluating the models pros, cons, and fit for different project stages. The goal is to refine a shared, open resource and identify unmet needs.</abstract>
                <slug>fossback26-83162-stable-software-needs-stable-funding-mapping-workshop</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84561'>Judith Fassbender</person>
                </persons>
                <language>en</language>
                <description>Sustaining FOSS projects continues to pose a challenge. As a funder, we are investigating in our research how combining different funding and resource models might offer viable solutions, and where gaps remain. In this workshop, we want to refine a map we are working on that captures different income and resource streams for FOSS projects.

We want to engage with the question of which (combinations) of those funding models can sustain which projects or project stages. Next to grants, donations, sales, and capital investments, we map, amongst others, models such as tiered licenses, corporate open source contributions, and contributions by students as part of their coursework. The search for a stable funding model is complicated by better or worse fits of different kinds of communities and software. We are further well aware that none of these models is likely to be a standalone solution to sustain a project and that each of them has its own difficulties.
Instead, we want to investigate how combinations of those can balance each other and support different projects and different project stages. In the workshop we want to walk through three tasks in three 10-15min rounds with you: 
 1. Add models that are missing from the map
 2. Specify pros and cons of the models
 3. Specify which projects are eligible for which models

The session will be closed by taking stock of what is missing: Which demands are not met by the array of listed approaches to sustain projects in the FOSS ecosystem. We welcome everybody interested and invite specifically people who are active in (F)OSS-projects and their support, to participate in reflecting on these questions with us and to contribute to the map. 

We fund innovative FOSS from society and for society, with funds from the Federal Ministry of Research, Technology and Space. This workshop is part of the research done in our organisation. We intend to make the map openly accessible after the workshop.

&lt;b&gt;This session is an interactive session and therefore not recorded.&lt;/b&gt;</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/TRCEGN/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='ec5f4d85-b8b7-52fb-82fb-682b1ed0075c' id='93783' code='MML79C'>
                <room>Wintergarten</room>
                <title>Secure by Design? Discussion on Voluntary Security Attestations</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-16T16:40:00+01:00</date>
                <start>16:40</start>
                <duration>00:30</duration>
                <abstract>With this discussion following the Chatham House Rule format, we wish to invite FOSS Backstage attendees to come together to explore how communities could issue risk-based attestations sufficient to reduce downstream compliance burdens in ways that support (rather than burden) open source communities.</abstract>
                <slug>fossback26-93783-secure-by-design-discussion-on-voluntary-security-attestations</slug>
                <track>Security</track>
                
                <persons>
                    <person id='86775'>&#198;va Black</person><person id='84793'>Gregor &quot;Little Detritus&quot; Bransky</person>
                </persons>
                <language>en</language>
                <description>The Cyber Resilience Act creates a transformative opportunity to strengthen both cybersecurity and the sustainability of open source through Article 25&apos;s voluntary security attestation framework.

We will examine practical implementation questions:
 - How do we balance proportional requirements with project maturity?
 - What governance models work for stewardship, as defined by the CRA?
 - How can attestations create sustainable funding flows to upstream communities without capture by commercial interests?

Your perspective will help determine whether this framework becomes a tool for sustainability or part of a regulatory barrier to open collaboration.

&lt;b&gt;This session is an interactive session taking place under &lt;a href=&quot;https://en.wikipedia.org/wiki/Chatham_House_Rule&quot; target=&quot;_blank&quot;&gt;Chatham House Rules&lt;/a&gt; and therefore not recorded.&lt;/b&gt;</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/MML79C/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-03-17' start='2026-03-17T04:00:00+01:00' end='2026-03-18T03:59:00+01:00'>
        <room name='Auditorium' guid='1ddd165f-4197-510d-a2af-9f0953509f9e'>
            <event guid='b237f9bb-c701-5303-b0a5-e6db819ff8e4' id='83218' code='DWU3AS'>
                <room>Auditorium</room>
                <title>Getting Real with the Supply Chain: From SBOM Data to Action</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:00:00+01:00</date>
                <start>10:00</start>
                <duration>00:30</duration>
                <abstract>500,000 SBOMs &#8211; that&#8217;s the scale of Deutsche Bahn&#8217;s software supply chain. How do we make sense of this as a small OSPO in a large non-IT organization? Our strategy: turn this data into actionable tasks. We&#8217;ll share practical learnings on prioritizing risks, applying sensible automated compliance, and considering ecosystem sustainability.</abstract>
                <slug>fossback26-83218-getting-real-with-the-supply-chain-from-sbom-data-to-action</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84625'>Max Mehl</person><person id='84724'>Cornelius Schumacher</person>
                </persons>
                <language>en</language>
                <description>The more insight we gain into our software supply chains, the more we face the challenge of acting on it. OSPOs must turn vast data into focused, meaningful decisions. This talk shares a risk-based framework we apply at Deutsche Bahn, designed to be broadly adoptable. It helps prioritize what truly matters: balancing compliance, governance, and sustainability.

We&#8217;ll discuss how we:

* manage regulatory obligations like CRA and NIS2 without overburdening teams
* set internal rules and automation that keep compliance practical
* identify real risks instead of chasing theoretical ones
* facilitate open source culture across the organization to understand and participate in communities
* include ecosystem health in our decisions

As a small virtual OSPO in a large non-IT company, we focus on pragmatic, incremental steps rather than perfect coverage. The session offers hands-on insights for anyone trying to make sense of large-scale SBOM data and turn transparency into responsible action.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/DWU3AS/resources/FOSS_Backstage__3ryi7Ld.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/DWU3AS/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0b277799-0242-53a6-8e65-5f0efe2be94f' id='83418' code='M9F7T8'>
                <room>Auditorium</room>
                <title>Saxony in Action: Supporting a Lasting FOSS Foundation</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:35:00+01:00</date>
                <start>10:35</start>
                <duration>00:30</duration>
                <abstract>What happens when a federal state truly supports open source? Granted by the state of Saxony, our funding project FOCIS helps ALASCA - Association for operational, open cloud-infrastructures e.V. grow into a more stable, independent home for FOSS projects. We&#8217;ll show how public support strengthens open source and what others can learn from Saxony.</abstract>
                <slug>fossback26-83418-saxony-in-action-supporting-a-lasting-foss-foundation</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84784'>Dr. Daniel Gerber</person>
                </persons>
                <language>en</language>
                <description>What happens when a federal state doesn&#8217;t just talk about supporting open source - but actually does it?

In this talk, we&#8217;ll share insights on how the state of Saxony is becoming a pioneer for open source in Germany: with a clear open source strategy and real financial support such as the publicly funded project FOCIS, which enables our non-profit association ALASCA to grow into a more stable, independent home for open source projects.

We&#8217;ll take you through our journey from a young association supported mostly by volunteers, to a professionally staffed organization that now supports six projects. With public funding, we were able to hire own employees, stabilize and expand existing governance structures, and lay the groundwork for a resilient open source foundation.

You&#8217;ll learn:

    How public funding can help in bootstrapping an open source foundation

    which benefits and support have been established using public funding

    What other communities or regions can take from this example

This talk is for anyone building or supporting open source communities - from maintainers and foundation organizers to policy makers and public sector advocates - who care about long-term sustainability, governance, and funding models.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/M9F7T8/resources/2026-03-16_FOSS_xWGKANM.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/M9F7T8/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2d8b9e13-65c7-540b-9732-d6d999c837fe' id='83342' code='HBW3UD'>
                <room>Auditorium</room>
                <title>Real accessibility: an imperfect, honest journey</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:20:00+01:00</date>
                <start>11:20</start>
                <duration>00:30</duration>
                <abstract>Compliance with legislation is not sufficient to build a good user experience, especially when maintaining an operating system used by millions. In this talk, we will share how we are building an accessibility practice that addresses the obvious and the non-obvious, and our learnings from this journey.</abstract>
                <slug>fossback26-83342-real-accessibility-an-imperfect-honest-journey</slug>
                <track>Diversity &amp; Inclusion</track>
                
                <persons>
                    <person id='84754'>Leia Ruffini</person><person id='84723'>Juan Ruiti&#241;a</person>
                </persons>
                <language>en</language>
                <description>Accessibility is as complex as human nature. Making a user experience that is genuinely accessible requires going beyond the letter of the law to address less obvious issues. For instance, it&#8217;s trivial to check if two colours have enough contrast; ensuring the language used in an app is easy to understand for everyone, not so much.

How can we create incredible accessible products? External agencies may help with audits, but accessibility should be an ongoing effort, not just a one-off project to address existing issues. New features should be accessible from the get-go, ideally validated with real-world users: easier said than done.

In this talk, we will share how creating a community of interest and tapping into our team&#8217;s diversity helped us come up with a more robust experience. We will also discuss the role of collaboration across disciplines including design, engineering, content and documentation, and how to facilitate community contributions to these efforts. Coming up with a better accessibility practice is not always a straight path, but is definitely a one worth taking.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/HBW3UD/resources/Real_accessibil_mmq8oHu.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/HBW3UD/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='8149951b-83fd-55cb-b925-781c923adfc0' id='82748' code='AAMAFC'>
                <room>Auditorium</room>
                <title>Building and scaling Hare&apos;s community governance</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:55:00+01:00</date>
                <start>11:55</start>
                <duration>00:30</duration>
                <abstract>How the Hare programming language community grew from one BDFL and a ragtag group of early hackers to a productive, sociable, and egalitarian community of happy hackers with a lightweight and effective model of participatory governance.</abstract>
                <slug>fossback26-82748-building-and-scaling-hare-s-community-governance</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84186'>Drew DeVault</person>
                </persons>
                <language>en</language>
                <description>The Hare programming language started in December 2019 with a small, secret prototype and gradually built out a community of curious adventure-seekers who stumbled into its open, but well-hidden, borders. Once unveiled to the public, this community&apos;s governance, policy-making, and day-to-day conduct of its affairs grew and evolved with careful deliberation into its present-day form, with 11 co-maintainers of various disciplines and over 100 contributors.

This talk will take the audience through each stage of this journey and highlight each of the changes made to its governance over time, explaining how each decision was weighed against our values and practices and helped us grow into a thriving community.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/AAMAFC/resources/main_MbUXiAQ.pdf">Slide deck</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/AAMAFC/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='33c8bc91-6b7e-5f8f-ae36-cec0b53bf459' id='83420' code='DS8DL8'>
                <room>Auditorium</room>
                <title>Balancing the Supply Chain Act</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-03-17T12:30:00+01:00</date>
                <start>12:30</start>
                <duration>00:40</duration>
                <abstract>Corporate users, volunteer maintainers, and everything in between, how can they work together? In this panel, we bring together different voices to explore: What does each side intend, expect, and need? And how can we bridge tensions in today&#8217;s open source supply chain?</abstract>
                <slug>fossback26-83420-balancing-the-supply-chain-act</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='89773'>Sarah Hoffmann</person><person id='84724'>Cornelius Schumacher</person><person id='84788'>Sven Jeroschewski</person><person id='87850'>Melanie Wollnik</person><person id='93632'>Tim Schmetzer</person>
                </persons>
                <language>en</language>
                <description>The typical software supply chain has many participants: open source communities, maintainers, companies, and others. There is a rising number of regulations, policies, and processes around that, for example, the Cyber Resilience Act or other security requirements. Expectations of companies sometimes do not match what the community can or wants to offer, and vice versa. The misalignment creates stress on both sides. How can this stress be resolved, so that all participants can benefit from one another and reap the advantages of open source, which has become ubiquitous wherever software is?

In the panel, we bring together representatives of different perspectives to discuss these questions. It will cover open source maintainers, companies using open source for internal services and for basing products on, and people working on processes.

List of participants:

* Moderator: Melanie Wollnik (OpenRail Association and DB Systel)
* Sven Erik Jeroschewski (Bosch Digital)
* Cornelius Schumacher (DB Systel)
* Tim Schmetzer (Osborne Clarke)
* Sarah Hoffmann (Open Street Map)

Together we&#8217;ll ask:

* What drives users vs maintainers in the open source supply chain?
* Where do expectations clash?
* How can process, governance and community shape better alignment?
* How can organizations and projects adapt to serve each other, not just co-exist?</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/DS8DL8/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='acf3dd1d-c91d-55f6-b22e-f145f549947f' id='82750' code='YVDBR7'>
                <room>Auditorium</room>
                <title>FOSS behind the scenes - the center stage is not enough</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T14:10:00+01:00</date>
                <start>14:10</start>
                <duration>00:30</duration>
                <abstract>Your code is FOSS, but the project uses all the famous and fancy proprietary platforms. Does it matter? Yes. Relying on non-free tools contradicts open source values and hurts your project. This talk pulls the curtain from the damages it makes, busts myths and gives you a director&apos;s cut commentary on how to be the hero your story needs.</abstract>
                <slug>fossback26-82750-foss-behind-the-scenes-the-center-stage-is-not-enough</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84187'>Jan Ainali</person>
                </persons>
                <language>en</language>
                <description>The goal of this talk is to spark reflection and conversation about the tools we use to build open source projects, not just the code we write. It is meant to encourage both new and experienced maintainers to think critically about how proprietary tools may, unintentionally, be limiting their communities and values. We&apos;ll explore how can we strengthen our open source ecosystem by reducing our dependency on tech giants and supporting community-owned infrastructure. The audience will leave with a better understanding of the trade-offs involved, where to take action, and the motivation to make small changes that lead to more open, inclusive, and resilient projects. 

Whether you&apos;re starting a new project or maintaining a mature one, this talk will challenge you to think critically about the tools you use and advocate for open, community-controlled alternatives that align with the spirit of FOSS.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links>
                    <link href="https://aina.li/backstage2026/">Slides</link>
                </links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/YVDBR7/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='43d09a00-91e8-5353-8205-f6156892d969' id='83125' code='VE7UEJ'>
                <room>Auditorium</room>
                <title>Navigating engineering-focused environments</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-03-17T14:45:00+01:00</date>
                <start>14:45</start>
                <duration>00:40</duration>
                <abstract>How can designers navigate in engineering-focused environments? This panel explores approaches for integrating UX into developer workflows and showcasing how design contributions are valuable assets for greater impact in engineering circles.</abstract>
                <slug>fossback26-83125-navigating-engineering-focused-environments</slug>
                <track>Design</track>
                
                <persons>
                    <person id='87179'>Eriol Fox</person><person id='84523'>Miguel Divo</person><person id='87313'>Gl&#242;ria Langreo</person><person id='87314'>David Edler</person>
                </persons>
                <language>en</language>
                <description>Open source often thrives on engineering-driven processes, where feedback loops, tools, and contributions are tailored to developers. But where does design fit in? This panel brings designers and engineers together to discuss how UX practices can be embedded in engineering workflows, from using GitHub as a design collaboration tool to framing design contributions in ways developers can get value from. 

Our panelists will share success stories and lessons from bridging design and engineering in open source. Their experiences as designers and engineers will bring different perspectives to uncover strategies and patterns for making design more visible and impactful in developer-focused environments. They will highlight what worked, what didn&#8217;t, and how their approaches evolved across projects and communities. 

Attendees will take away ideas for embedding design into engineering-focused environments, and inspiration from projects where cross-disciplinary collaboration has led to better user experiences and stronger collaboration.

Interested in embedding design thinking into the engineering world? Join us!</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/VE7UEJ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='f804f95d-4844-59a0-95dc-12c6c2b53a96' id='83327' code='TLLJBF'>
                <room>Auditorium</room>
                <title>The OpenStreetMap Community</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T15:50:00+01:00</date>
                <start>15:50</start>
                <duration>00:30</duration>
                <abstract>Over the last 20 years the OpenStreetMap (OSM) project has collected an enormous amount of data about our planet and written a lot of Open Source software. OSM-based maps and apps are everywhere. How do you organize two million contributors in a mostly volunteer project to work on a common goal? And what exactly is that common goal?</abstract>
                <slug>fossback26-83327-the-openstreetmap-community</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84701'>Jochen Topf</person>
                </persons>
                <language>en</language>
                <description>OpenStreetMap creates, collects and delivers Open Data about our world. But it is more: It is a worldwide community and a human cultural endeavour. The OSM community, that is millions of volunteers, but also companies large and small, and organisations from the UN down to the local hiking club. How do we organize all of this with an extremely slim (and maybe too slim?) governance structure that is still mostly based on volunteer work? Where does this work and where are the problems? What makes it similar to other digital commons projects and what makes it different? What can we learn from other communities like ours?</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/TLLJBF/resources/2026-03-17-talk_i1X3Cjm.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/TLLJBF/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='72ba4970-263e-5939-be01-12774f52dcf7' id='83059' code='SSZGTE'>
                <room>Auditorium</room>
                <title>Plan to fork (So you don&apos;t have to fork)</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T16:25:00+01:00</date>
                <start>16:25</start>
                <duration>00:30</duration>
                <abstract>Writing a detailed plan to fork, as a disaster recovery plan for tomorrow, is a great way to identify places where you sould be investing more deeply in an open source project, today.</abstract>
                <slug>fossback26-83059-plan-to-fork-so-you-don-t-have-to-fork</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84448'>Rich Bowen</person>
                </persons>
                <language>en</language>
                <description>If your product or service relies on an open source project, ensuring the sustainability of that project is just good business sense. Forking that source project should be a last resort, to be considered only after all other options have been exhausted. But writing a detailed plan to fork has two benefits. First, it ensures that should the worst happen, you&#8217;ve already considered how you&#8217;ll deal with it. But perhaps more importantly, thinking proactively about forking will help you take actions that will ensure that it never gets to that.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/SSZGTE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='78346602-0b2f-5902-81ff-30b4f81eeafb' id='82713' code='RES9SW'>
                <room>Auditorium</room>
                <title>Lessons from 10+ Years of Certifying Open Source Hardware</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T17:00:00+01:00</date>
                <start>17:00</start>
                <duration>00:30</duration>
                <abstract>Over the past decade, the Open Source Hardware Association has certified thousands of pieces of hardware from almost 70 countries as open. We&apos;ve learned some things and want to share!</abstract>
                <slug>fossback26-82713-lessons-from-10-years-of-certifying-open-source-hardware</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84148'>Michael Weinberg</person>
                </persons>
                <language>en</language>
                <description>In 2015, the Open Source Hardware Association (OSHWA) kicked off the process of creating an open source hardware certification.[1] In the decade since, OSHWA has certified thousands of pieces of hardware from over 60 countries on 6 continents [2] as compliant with the community definition of open source hardware.[3]

This presentation will discuss why the certification program was created in the first place, how it is being used today, and what lessons other communities might be able to learn from its success. 

[1] https://certification.oshwa.org/ [2] https://certification.oshwa.org/list.html [3] https://www.oshwa.org/definition/</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/RES9SW/resources/Weinberg_10_Yea_I44l8UV.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/RES9SW/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='bUm Box' guid='deb473ee-a453-5811-bbc3-605d58e50a3e'>
            <event guid='f53e38fc-28dd-5595-b884-7dc36dd964cf' id='82534' code='RJPA3K'>
                <room>bUm Box</room>
                <title>The Power of Dedicated Security Engineers vs. Volunteers</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:00:00+01:00</date>
                <start>10:00</start>
                <duration>00:30</duration>
                <abstract>Open source security is often overlooked until a crisis hits. This talk compares the impact of volunteers versus dedicated full-time security engineers in the Python and Ruby ecosystems. It highlights how consistent investment strengthens community resilience, reduces risk, and proves that security isn&#8217;t a cost but an essential strategy.</abstract>
                <slug>fossback26-82534-the-power-of-dedicated-security-engineers-vs-volunteers</slug>
                <track>Security</track>
                
                <persons>
                    <person id='84000'>Miaolai Zhou</person>
                </persons>
                <language>en</language>
                <description>Perfect security works like a transparent umbrella &#8212; it shields you from the storm, often without you realizing there&#8217;s one. That invisibility, however, is why open source security is too often seen as a cost rather than a strategic investment.
Most organizations only start paying attention to security after a crisis &#8212; think Log4j &#8212; when it&#8217;s already too late. In the open source world, many projects depend on volunteers to respond to security incidents. Their contributions are invaluable, but what happens when projects have dedicated, full-time security engineers instead?
In this session, we&#8217;ll explore that question through the stories of Mike, Seth, and Samuel, who once volunteered their time supporting security in the Python and Ruby ecosystems. With funding from AWS and Alpha-Omega, they later became full-time security engineers employed by the Python Software Foundation and Ruby Central.
By comparing their impact as volunteers versus full-time professionals, we&#8217;ll quantify the value of dedicated security investment and measure its return on investment.
Open source is everywhere &#8212; securing it benefits everyone. Through this talk, we&#8217;ll challenge you to rethink security not as an afterthought or a cost center, but as a core strategy worth proactive investment.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/RJPA3K/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='17fae80a-b3e2-5d3f-b9e0-6013fd4ba8d1' id='83346' code='GPKF7H'>
                <room>bUm Box</room>
                <title>How Open Collective moved from a for-profit to a non-profit</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:35:00+01:00</date>
                <start>10:35</start>
                <duration>00:30</duration>
                <abstract>The largest users of the Open Collective Platform set up a coup and ousted the initial investors. We are now a 501(c)(6) membership nonprofit. We would love to share how our governance has evolved, our current challenges in achieving financial sustainability, and how we have contributed to the open-source ecosystem. https://blog.opencollective.com</abstract>
                <slug>fossback26-83346-how-open-collective-moved-from-a-for-profit-to-a-non-profit</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84727'>Shannon Wray</person>
                </persons>
                <language>en</language>
                <description>The Open Collective Platform has been a big advocate for open-source since it&apos;s inception in 2015. Not only have we helped the open source ecosystem but it has supported our growth in return. The largest Fiscal Host on our platform is Open Source Collective. The true open-source back office star. Ensuring the legal and accounting compliance of over 3000 open-source projects. 

Our platform enables these projects to transparently showcase their financials. Highlighting the critical gaps in funding and encouraging collaborative ownership. https://discover.opencollective.com/opensource

Open Source Collective has been a key instigator in freeing the platform from it&apos;s venture capital history and pursing true community ownership. We would love to celebrate this and dive into how this was negotiated. 

It&apos;s one thing to take the step and become community owned, it&apos;s an entirely different reality to shape the shared governance and put our words into action. While we are still grappling to find our footing and achieve financial sustainability. We would love to share the governance processes we have implemented and the key challenges we have faced. What was sacrificed and lost in the process and what challenges do we still need to navigate.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/GPKF7H/resources/Shannon_Wray_-__bN3dYpK.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/GPKF7H/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='f8fc6375-1663-59b4-9f12-4d4bdc1d28c1' id='83360' code='RZMDHZ'>
                <room>bUm Box</room>
                <title>Why Has Hardware Infrastructure Diverged From Open Software?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:20:00+01:00</date>
                <start>11:20</start>
                <duration>00:30</duration>
                <abstract>Open software thrives through open tools and collaboration. Hardware remains trapped behind prohibitively expensive tool licenses and limited foundry access. Why? This talk explores the structural barriers preventing hardware from following software&apos;s path, and why solving them requires entirely new institutional forms, not just better policies.</abstract>
                <slug>fossback26-83360-why-has-hardware-infrastructure-diverged-from-open-software</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84740'>Tara Tarakiyee</person>
                </persons>
                <language>en</language>
                <description>Open source software transformed computing through collaborative infrastructure. Why hasn&apos;t open hardware followed? Despite decades of advocacy and similar technical collaboration potential, we still face expensive tool licenses, foundry barriers, and fragmented volunteer projects. This isn&apos;t an accident, it&apos;s the result of the biggest industrial policy failure of the last century. 

**Three Critical Divergences**
Capital intensity: Software tools scale to reasonable costs, once built, they can distributed generally at low-cost. Hardware requires unavoidable physical capital: &#8364;100K-&#8364;1M annual EDA licenses, &#8364;500K-&#8364;2M foundry access minimums, substantial prototyping costs. This creates fundamentally different economic dynamics that can&apos;t be overcome through better licensing or community organizing.

Institutional vacuum: Open software largely succeeded because new organizational forms emerged to employ maintainers, coordinate development, and provide infrastructure at scale. Open hardware has no equivalent institutional layer. Universities produce research, not production tools. Companies optimize for proprietary capture. Traditional foundations lack capacity to employ hundreds of engineers or deploy patient capital. Governments fund research grants, not operational infrastructure. The missing piece is the organizational capacity to build and maintain technology commons.

Revenue generation: Software can monetize through services, support, and usage, value extracted without controlling physical production. Hardware value concentrates in intellectual property, manufacturing and supply chains, making service-based sustainability far harder. This determines which organizations can viably build hardware commons long-term.

**Why the FOSS Community Should Care:**
Hardware is becoming the constraint on software freedom. European tech companies pay billions annually in proprietary tool licensing. Supply chain concentration creates strategic vulnerabilities, and geopolitical tensions could cut access to critical design tools or fabrication. Digital sovereignty requires open hardware foundations, not just open software. Without addressing this, FOSS gains remain dependent on proprietary infrastructure.

What You&apos;ll Learn:

Why replication fails: Software&apos;s organizational models don&apos;t transfer to hardware due to structural economic barriers. You can&apos;t create &quot;Apache Foundation but for chip design&quot; because the capital requirements, employment scale, and revenue dynamics are categorically different.

The missing institution: What would an &quot;Open Hardware Infrastructure Works&quot;, a public institution maintaining open hardware infrastrucutre, might look like? What would an institution like that be able to do to level the playing field and open up hardware development? How would an institution like that be financed? What can we learn from precedents: adapting models from highway authorities, utility companies, and transnational consortia for big infrastructure projects?

This isn&apos;t about better funding models or governance reforms. It&apos;s recognizing that hardware commons require institutional forms that don&apos;t yet exist. Just as societies created new organizational types for railroads, electrification, and telecommunications, we need purpose-built institutions for 21st-century technology infrastructure. The question isn&apos;t whether open hardware is desirable, that is clear, it&apos;s whether we can design and build organizations capable of developing it at competitive scale.

This talk is relevant for anyone working on digital sovereignty, FOSS sustainability, supply chain resilience, institutional design, or infrastructure commons, and anyone frustrated that hardware seems perpetually behind software in open development despite equivalent technical collaboration potential.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/RZMDHZ/resources/TaraTarakiyeeH_lb9OeMU.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/RZMDHZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='2ad2309b-d6d9-5ba8-bb77-078b131681f8' id='83440' code='SUZPJ7'>
                <room>bUm Box</room>
                <title>Fair Share Cost Tokens</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:55:00+01:00</date>
                <start>11:55</start>
                <duration>00:30</duration>
                <abstract>The Cyber Resilience Act (CRA) will require FOSS projects to step up their security and, following the logic of the FOSS ecosystem, produce attestation for their software.

This talk introduces fair-share cost tokens - a feature which supports financial flows along open source software supply chains. (No blockchain)</abstract>
                <slug>fossback26-83440-fair-share-cost-tokens</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84793'>Gregor &quot;Little Detritus&quot; Bransky</person>
                </persons>
                <language>en</language>
                <description>The goal of this talk is to provide an overview of the economic component of the CRA attestation project [1].

Fair-share cost tokens are cryptographically signed tokens which allow manufacturers to prove that they are making their &quot;fair&quot; contribution to the
health of their FOSS Ecosystem. Whenever a commercial software producer - a manufacturer in terms of the CRA - includes FOSS code maintained by a legal entity - an Open Source Software Steward in terms of the CRA - the token is used for attestation. Thus, the two parties can create a communication channel in case of a security incident. The same mechanisms should allow to bring resources deeper into the supply chain, as it can also be used by software stewards to allocate resources towards stewards whoms codebase they are using.

Frameworks like SCITT [2] and Omnibor [3] could allow for their technical implementation. However, some policy work is required to make the situation of potential FOSS projects in the EU compatible with 501 (c) 3&#180;s in the US.

[1] https://github.com/orcwg/cra-attestations
[2] https://datatracker.ietf.org/wg/scitt/about/
[3] https://omnibor.io/project/</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/SUZPJ7/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='900ccc0a-20ae-5148-bd3c-e0705e1db791' id='83431' code='DRSUPK'>
                <room>bUm Box</room>
                <title>Keeping the flame alive: storytelling for open source</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T12:30:00+01:00</date>
                <start>12:30</start>
                <duration>00:30</duration>
                <abstract>A brand isn&#8217;t just a logo, it&#8217;s the story people tell each other about what you stand for. In open source, that story builds trust, sparks curiosity, and inspires contribution. This talk explores how storytelling and brand design can create welcoming open source projects.</abstract>
                <slug>fossback26-83431-keeping-the-flame-alive-storytelling-for-open-source</slug>
                <track>Design</track>
                
                <persons>
                    <person id='84790'>Nicole Weber</person>
                </persons>
                <language>en</language>
                <description>Open source runs on community, and communities run on stories. A good story gives people a reason to join, stay, and care. 

In this session, we&#8217;ll explore how storytelling can strengthen open-source communities and help&#160;build trust&#160;and excitement. We&#8217;ll look at practical examples of how to tell a story with visual design and what role motion, iconography, tone and voice, or color play. 

I&#8217;ll also share practical tools to help teams maintain their story over time that help align contributors around a common message. 

By the end, you&#8217;ll leave with an actionable framework that connects people and builds trust, and keeps the open-source flame burning bright.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/DRSUPK/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='ae7a7376-98d9-5dee-a847-92c36aa8cdc6' id='83214' code='CYZPLB'>
                <room>bUm Box</room>
                <title>Why Open Standards Power Compliance</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T14:10:00+01:00</date>
                <start>14:10</start>
                <duration>00:30</duration>
                <abstract>Free and open standards, and the open processes behind them, can lay the foundation for innovation, interoperability, and compliance across EU digital, environmental, and industrial policies. Drawing on the Linux Foundation&#8217;s State of Open Standards report, this talk explores their potential to strengthen regulation, trust, and competitiveness.</abstract>
                <slug>fossback26-83214-why-open-standards-power-compliance</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84622'>Madalin Neag</person>
                </persons>
                <language>en</language>
                <description>In an increasingly digitalized Europe, legislation such as the Digital Markets Act, AI Act, and Cyber Resilience Act, depend on technology-neutral, interoperable frameworks to achieve their goals. Free and open standards, together with transparent and inclusive standardization processes, are emerging as essential tools for effective and accountable regulation.
Drawing on the Linux Foundation&#8217;s report, The State of Open Standards, Standardization and Patents in Organizations, this session explores how open standards are becoming a pillar of digital policy implementation. The research shows that nearly 80% of organizations view standardization as vital for compliance and strongly favor openly developed standards over proprietary or closed models.
We will examine three interconnected policy dimensions:
Why open standards matter for Europe and how they reduce dependency, enhance interoperability, improve quality, and advance strategic autonomy while supporting legislative aims such as transparency, data portability, and resilience.
What attributes drive trust and adoption: how openly published, consensus-based, and extensible standards strengthen compliance, innovation, and public confidence.
How policy can embed openness and the practical approaches for European institutions, standardization bodies, and industry to align around &#8220;free and open&#8221; standards as enabling infrastructure. This includes integrating open standards into procurement frameworks, certification schemes, and public-private partnerships.
The discussion will also consider the evolving role of standard-essential patents (SEPs) and the balance between openness, innovation, and fair intellectual property practice.
Attendees will leave with actionable insights on how to integrate open-standards thinking into policy design, regulatory compliance, and procurement strategy, turning evolving EU mandates into an opportunity for digital resilience and sustainable competitiveness.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/CYZPLB/resources/Why_Open_Standa_fNVORBV.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/CYZPLB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='1c22a311-8c74-56a3-aada-9a413820052d' id='83416' code='UGV9LX'>
                <room>bUm Box</room>
                <title>A fork load of maintenance - forking a key dependency</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T14:45:00+01:00</date>
                <start>14:45</start>
                <duration>00:30</duration>
                <abstract>This talk explores the BBC&#8217;s experience maintaining a fork of dash.js for media playback. It covers the motivations, trade-offs, and strategies to reduce maintenance overhead - such as upstream contributions and community engagement.</abstract>
                <slug>fossback26-83416-a-fork-load-of-maintenance-forking-a-key-dependency</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84782'>Tom Sadler</person><person id='89744'>Joel Keers</person>
                </persons>
                <language>en</language>
                <description>The benefits of building software on top of open source solutions are well understood, such as avoiding reinventing the wheel, leveraging global expertise, and enabling interoperability. Another benefit is the ability to customise open source software for your use case, but in practice this will often be done by making a fork of the project, which can result in a significant maintenance overhead.

This talk is a case study of the BBC&apos;s fork of dash.js, a JavaScript library for media playback that is a key dependency for BBC web and connected TV apps. We will explore the reasons why a fork is being maintained, what the costs and benefits have been, and what is being done to reduce the maintenance overhead going forwards, including contributing to the mainline and engaging with the community. Attendees will come away with a better understanding of why and why not to fork, and how to reduce the burden of maintaining a fork.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/UGV9LX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='4251d8ca-f07b-57aa-9624-51ff12654643' id='83202' code='CYZZHS'>
                <room>bUm Box</room>
                <title>We need a European Sovereign Tech Fund!</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T15:50:00+01:00</date>
                <start>15:50</start>
                <duration>00:30</duration>
                <abstract>We have conducted an in-depth study into the political, legal and economic feasibility of an EU Sovereign Tech Fund (EU-STF), a fund for the maintenance of open source infrastructure, building on the successful example of the German Sovereign Tech Agency. Learn about our findings and how you can help us make the EU-STF a reality.</abstract>
                <slug>fossback26-83202-we-need-a-european-sovereign-tech-fund</slug>
                <track>Economics</track>
                
                <persons>
                    <person id='84610'>Felix Reda</person><person id='84752'>Nicholas Gates</person>
                </persons>
                <language>en</language>
                <description>This talk is a call-to-action to join our campaign to convince the European Union that, in order to secure its digital future, it should invest in open source maintenance via an EU Sovereign Tech Fund (EU-STF).

Right now, the EU is negotiating its multi-year budget for the period of 2028-2034. Traditionally, the EU budget has been focused on regional development and agriculture, but more and more policymakers are realizing that investment in our digital infrastructure is just as important as maintaining physical roads and bridges. We have conducted an in-depth study into the political, legal and economic feasibility of an EU fund for open source maintenance, building on the successful example of the German Sovereign Tech Agency. We assembled a coalition of supporters from industry and civil society, and we have presented our proposal to the European Parliament and Member States.

Now it&#8217;s time to take the campaign to the next level and we need your support to make it happen. The goal of this session is to present the high-level design principles of the EU-STF and demonstrate why mission-driven investment, coordinated by the public sector, is important for the diversification of Europe&#8217;s funding landscape. It will demonstrate how such a proposal can directly improve the sustainability and health of the open source community globally, and why this is so important for Europe in achieving its digital future.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/CYZZHS/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='1b4b0943-2bc8-5eeb-955d-09352fe5f247' id='83350' code='JLKZQX'>
                <room>bUm Box</room>
                <title>Let&#8217;s tackle Openwashing!</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T16:25:00+01:00</date>
                <start>16:25</start>
                <duration>00:30</duration>
                <abstract>Companies that develop Free Software face a problem: competitors disguising proprietary software as &#8220;open&#8221; and undercutting Free Software products in public tenders. Such practices distort competition and undermine strategic procurement and digital sovereignty. Which openwashing methods are used, and what can be done about it?</abstract>
                <slug>fossback26-83350-let-s-tackle-openwashing</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84730'>Johannes N&#228;der</person>
                </persons>
                <language>en</language>
                <description>Openwashing has become a growing challenge for users, developers, and public administrations, and for the entire Free Software ecosystem. Using various methods, some companies advertise their products as &#8220;free&#8221; or &#8220;open&#8221;, while in reality distributing proprietary software. The supposed creativity of these openwashers is remarkable: whether by using free/open wording, by introducing new licences that falsely appear to be free, or by imposing additional barriers that make it more difficult to use the freedoms offered by Free Software.

This misleading behaviour undermines efforts to achieve digital sovereignty through Free Software. It weakens strategic procurement aimed at ensuring that public money funds Free Software, as promoted by the Free Software Foundation Europe&#8217;s &quot;Public Money? Public Code!&quot; initiative. It also distorts competition, misleads customers, and erodes trust in the Free Software ecosystem.

The FSFE has been analysing openwashing and other questionable market practices over the past years. In this talk, we will look at concrete examples and examine how they harm Free Software manufacturers and maintainers. Finally, we will discuss what administrations, regulators, and the Free Software community can do to curb openwashing.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/JLKZQX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='8f45440f-30ca-550a-95aa-efb748aeee5c' id='83201' code='DXMQXU'>
                <room>bUm Box</room>
                <title>Best practices and (very) small projects</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T17:00:00+01:00</date>
                <start>17:00</start>
                <duration>00:30</duration>
                <abstract>Most open source software is not maintained by a large community but by a single person in limited time. For them, best practices developed in large projects might not be feasible to apply &#8211; but what can be done instead?</abstract>
                <slug>fossback26-83201-best-practices-and-very-small-projects</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84609'>Jan Dittrich</person>
                </persons>
                <language>en</language>
                <description>Most open source software is not maintained by a large community but by a single person in limited time. Hobbyist maintainer projects have previously been discussed from the perspective of security risks and reliance of complex ecosystems on single actors (cue XKCD 2347 &quot;Dependency&quot;), but this talk will focus the tools and work methods at the hand for these developers in regards to community building, usability and documentation.  
A lot of practices that might be helpful to improve software imply the availiability of resources, most importantly team with diverse, complementary skills. But most maintainers do not have access to these resources. 
I suggest that we need an awareness and appreciation of small project and a critical review of tools and work methods for their fit for the situation of small projects. I will use examples from usability to show the problems of many commonly recommended methods as well as alternatives that are better suited.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links>
                    <link href="https://opensourcesecurity.io/2025/08-oss-one-person/">&quot;Open Source is one person&quot; by Josh Bressers</link>
                </links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/DXMQXU/resources/SmallProjectsAn_os7O0U0.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/DXMQXU/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Wintergarten' guid='888139d6-e46d-5d53-b8d2-844aa948a342'>
            <event guid='a4581074-1e7a-5d18-97bc-edbfc76c1a5a' id='81591' code='N7WTHZ'>
                <room>Wintergarten</room>
                <title>Docs, Demos, and Mentors: Growing Open Source</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:00:00+01:00</date>
                <start>10:00</start>
                <duration>00:30</duration>
                <abstract>&quot;Why aren&#8217;t more people contributing?&quot;

Contributors are the lifeblood of open source, yet many projects struggle to grow beyond a small core team. 

In this workshop, you will learn simple, hands-on techniques to get more people contributing to open source projects.</abstract>
                <slug>fossback26-81591-docs-demos-and-mentors-growing-open-source</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='83087'>Mustapha Rufai</person>
                </persons>
                <language>en</language>
                <description>Why do promising open source projects struggle to attract and keep contributors? 

After training 2,000+ developers across Africa and Europe and leading community engagement for 10,000+ API users at Paga, I&#8217;ve seen the answer firsthand: contributors vanish when documentation is dense, demos are missing, or mentorship is nonexistent.

This talk transforms those gaps into growth engines. 

I&#8217;ll break down three pillars to turn your project into a self-sustaining contributor magnet:

A. Docs as Onboarding Engines
i - Transform static guides into interactive pathways that welcome newcomers and accelerate their first PR.

B. Demos as Trust Builders
i - Use lightweight, reproducible examples (e.g., GitHub Codespaces) to prove your project&#8217;s value in seconds&#8212;not hours.

C. Mentors as Multipliers
i - Design scalable mentorship models that pair newcomers with experienced contributors without burning out maintainers.

You&#8217;ll walk away with:

1 - A playbook to make docs actionable, demos irresistible, and mentorship sustainable.

2 - Metrics that matter: time-to-first-PR, repeat contribution rates, and retention benchmarks.

3 -Anti-burnout strategies to operationalize growth while protecting maintainer energy.

Drawing from global projects (like Kubernetes) and local communities I&#8217;ve supported), this session answers the questions every maintainer asks:

&quot;Why aren&#8217;t more people contributing?&quot;
&quot;How do we scale without adding more maintainers?&quot;

If you&#8217;re tired of answering the same beginner questions or watching contributors slip away&#8212;this is your roadmap to resilient growth.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/N7WTHZ/resources/RufaiMustapha_b_VsiInBb.pdf">Slides (PDF)</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/N7WTHZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='df9c4903-4b5e-54eb-959c-19dbba4813e6' id='83116' code='XUFL3H'>
                <room>Wintergarten</room>
                <title>Lessons from Prometheus&apos;s First Design Mentorship</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T10:35:00+01:00</date>
                <start>10:35</start>
                <duration>00:30</duration>
                <abstract>What happens when a developer-first open source project tries UX research for the first time? This talk tells the story of Prometheus&apos;s first UX mentorship and explores the reality of introducing research to a dev-first community. Was it worth it? Will they do it again? And what can other OSS projects learn from their experience?</abstract>
                <slug>fossback26-83116-lessons-from-prometheus-s-first-design-mentorship</slug>
                <track>Design</track>
                
                <persons>
                    <person id='84514'>Victoria Nduka</person>
                </persons>
                <language>en</language>
                <description>When I joined the Prometheus project through the [Linux Foundation Mentorship](https://mentorship.lfx.linuxfoundation.org/project/36e3f336-ce78-4074-b833-012015eb59be) program, UX research wasn&#8217;t something the community had ever done before. Prometheus is a mature, developer-focused open source project, so introducing UX research meant stepping into new territory&#8212;for both me and the community.

This talk shares what that experience looked like: the messy but rewarding process of doing UX in the open, learning to align design with a developer culture, and building trust in a space where design wasn&#8217;t yet a familiar practice. It also looks at what happened after the research: the impact on the project, the momentum it created for future design work, and how Prometheus continues to nurture design contributions today.

Key takeaways:
- Candid lessons from integrating design into technical open source communities
- What helps design efforts become part of the community, not just a one-time experiment
- Practical insights for projects considering design contributions and for designers exploring open source.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/XUFL3H/resources/Lessons-from-Pr_166pTPR.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/XUFL3H/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='38137707-90eb-572b-ad5f-a5ad1359e634' id='83387' code='8GXJZB'>
                <room>Wintergarten</room>
                <title>Narrative Infrastructure: Storytelling to Grow Open Source</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:20:00+01:00</date>
                <start>11:20</start>
                <duration>00:30</duration>
                <abstract>Open-source ecosystems run on more than code, they run on story. Beyond commits, shared narratives sustain trust and belonging. At WriteTech Hub, we turned storytelling into infrastructure, every doc review, milestone, and mentor invite reinforced one truth, you belong here, and what you build matters.</abstract>
                <slug>fossback26-83387-narrative-infrastructure-storytelling-to-grow-open-source</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84764'>Zainab Daodu</person>
                </persons>
                <language>en</language>
                <description>Every open community runs on more than code, it runs on story. In this talk, I&#8217;ll explore how storytelling can be used as narrative infrastructure to build stronger, more inclusive open-source communities. Drawing from my experience leading WriteTech Hub and contributing to open documentation initiatives, I&#8217;ll show how narrative can align diverse contributors, spark engagement, and sustain collaboration over time.
We&#8217;ll unpack practical ways storytelling can humanize onboarding, strengthen contributor identity, and create trust in open ecosystems. Attendees will leave with simple frameworks to use story as a tool for communication, governance, and culture-building.
At a time when contributor burnout and disengagement are rising, this talk offers a fresh, human-centered approach, helping communities reconnect with why they build, not just what they build</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/8GXJZB/resources/Zainab_Daodu_Na_J7wiCGH.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/8GXJZB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='949e5313-48dc-5c35-b03e-d6fd3dca2928' id='83225' code='HMCHND'>
                <room>Wintergarten</room>
                <title>Bridging the Gap: Encouraging African Talent to Open Source</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T11:55:00+01:00</date>
                <start>11:55</start>
                <duration>00:30</duration>
                <abstract>Africa is rich in tech talent, many of whom are eager to contribute to open-source projects. However, due to the technical requirements needed to get started with open source and a lack of proper mentoring and guidance from these communities, many talents are discouraged. This talk explores ways to mitigate this problem.</abstract>
                <slug>fossback26-83225-bridging-the-gap-encouraging-african-talent-to-open-source</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='84629'>Seyi Kuforiji</person>
                </persons>
                <language>en</language>
                <description>Africa has a talented pool of tech enthusiasts. In recent years, there has been a meteoric rise in the number of young people in Africa actively learning tech skills and aspiring to be part of the future. Despite Africa&#8217;s growing developer population, African contributors remain underrepresented in open source. In this talk, I&#8217;ll share my journey into open source as an Outreachy intern working on the Git project and highlight the problems that many African developers face, from limited access to resources to a lack of awareness and socio-economic hurdles. I&#8217;ll explore practical ways we as a community can bridge these gaps through mentorship, outreach, and inclusive programs.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/HMCHND/resources/Seyi_Kuforiji_B_OencTZX.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/HMCHND/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='dbf029f3-4a8a-5747-a876-49d477ac48d7' id='83037' code='K9HLLE'>
                <room>Wintergarten</room>
                <title>Educating the next generation of open source contributors</title>
                <subtitle></subtitle>
                <type>Panel</type>
                <date>2026-03-17T12:30:00+01:00</date>
                <start>12:30</start>
                <duration>00:40</duration>
                <abstract>There are so many open source projects and not enough contributors to sustain them all over the long term. With many open source projects desperate for contributors, how do we educate the next generation of open source contributors to grow the contributor base for all of us?</abstract>
                <slug>fossback26-83037-educating-the-next-generation-of-open-source-contributors</slug>
                <track>Growing Open Source</track>
                
                <persons>
                    <person id='87135'>Ruth Ikegah</person><person id='84427'>Dawn Foster</person><person id='87134'>Peculiar C. Umeh</person><person id='87133'>Stephen Walli</person>
                </persons>
                <language>en</language>
                <description>Open source is the foundation of modern software, yet many projects struggle with sustainability, not just in attracting contributors, but in ensuring they stay, grow, and thrive. The landscape of open source contribution has evolved dramatically, demanding a fresh approach to educating potential contributors as part of broader community building and contributor engagement strategies.

Every educational program depends on participant support for projects and mentors towards the programs&#8217; outcomes, and we need industry participation to make these programs successful. The only way for these programs to scale to the growing and various needs of program organizers is for more people to understand how these programs work and how to engage with these programs to support their own diverse needs to grow the broad open source contributor pool. By getting a wide variety of industry support from companies and the maintainers who are employed by these companies, we can create educational programs where students learn the skills that they need to participate in open source projects and become our next generation of contributors.

In this panel, we&#8217;ll talk about education programs for our youth and university students. We&#8217;ll discuss the landscape of open source contributors in the different regions along with the motivations for participation in open source and how those differ across regions. Because we want contributors who will continue contributing, we&#8217;ll also talk about some challenges that prevent sustainable contributions over the long term.

Our panelists have experience teaching open source to university students, creating and sustaining open source education and contribution programs, and building new open source communities in Africa. In this panel, we&#8217;ll talk about what we&#8217;ve learned, what&#8217;s worked, and provide tips for you to grow the next generation of contributors from within your local communities. This talk presents attendees with a breadth of perspectives on educational programs, how they work, and how we can all work together to make them successful.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/K9HLLE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='97bb85ce-f7fc-5bc1-8af9-97632023a0fc' id='81164' code='A9UTRX'>
                <room>Wintergarten</room>
                <title>Everyone Belongs to Open Source</title>
                <subtitle></subtitle>
                <type>Workshop</type>
                <date>2026-03-17T14:10:00+01:00</date>
                <start>14:10</start>
                <duration>01:00</duration>
                <abstract>In this hands-on workshop, we&#8217;ll create a No-Code Contribution Map to show how skills like writing, design, outreach, and accessibility promote adoption and inclusion. Leave with strategies to grow diverse, welcoming, and sustainable communities.</abstract>
                <slug>fossback26-81164-everyone-belongs-to-open-source</slug>
                <track>Diversity &amp; Inclusion</track>
                
                <persons>
                    <person id='82615'>Cynthia Udoh</person>
                </persons>
                <language>en</language>
                <description>For open source to reach new audiences and grow sustainably, it must welcome and recognize more than code. Skills like event organizing, technical writing, design, and accessibility advocacy are vital to promoting adoption and building inclusive communities. Yet many projects still lack structures that value these contributions.

This 60-minute workshop reframes diversity and inclusion in open source by demonstrating how non-code contributions are powerful tools for outreach and growth. Participants will reflect on their own skills, map them to real project needs, and collaboratively create a No-Code Contribution Map, a framework that connects diverse abilities to concrete ways of promoting and sustaining open source.

We will also explore practices that support inclusivity: onboarding pathways for non-technical contributors and recognition systems that ensure everyone feels they belong.

Learning Outcomes:

Understand how non-code contributions promote adoption and inclusion.
Build a practical No-Code Contribution Map for open source projects.
Gain strategies for designing contributor journeys that welcome everyone.
Learn inclusive practices that strengthen open source outreach and growth.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://program.foss-backstage.de/media/fossback26/submissions/A9UTRX/resources/Everyone_Belong_09osNB4.pdf">Slides</attachment>
                </attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/A9UTRX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='60fa5ee2-8516-5a92-a4d4-ceac4c6f6605' id='82845' code='BQPCUJ'>
                <room>Wintergarten</room>
                <title>Free as in Friendship</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-03-17T15:50:00+01:00</date>
                <start>15:50</start>
                <duration>00:30</duration>
                <abstract>&quot;It&apos;s free as in speech, not free as in beer.&quot; But is &apos;free speech&apos; the kind of freedom FOSS projects should aim for? Should we instead focus on positive freedoms&#8212;not just the right, but the ability to achieve our aims? This talk argues for the latter, and charts a course for how to do so, drawing from the psychology framework of intersubjectivity.</abstract>
                <slug>fossback26-82845-free-as-in-friendship</slug>
                <track>Governance &amp; Community</track>
                
                <persons>
                    <person id='84269'>Shauna Gordon-McKeon</person>
                </persons>
                <language>en</language>
                <description>&quot;It&apos;s free as in speech, not free as in beer.&quot; How many times have you heard people define free software this way? But free speech, as important as it is, is only one kind of liberty. When we think of freedom only in terms of freedom from restraint&#8212;the restraint of government censors, or the restraints of proprietary licenses&#8212;we miss out on whole other categories of freedom.

&quot;Positive liberties&quot; are those we enjoy through the support of others. They are &quot;freedom to&quot;, not &quot;freedom from&quot;. Positive liberties tend to be harder to define and harder to realize than negative freedoms. For example, if a piece of FOSS is difficult to modify, the user may have &quot;freedom from&quot; prosecution for modifying the software, but no real &quot;freedom to&quot; modify it. And not because the maintainers don&apos;t want to give them that freedom! But &quot;freedom to&quot; is often complicated, messy and contextual.

This talk charts a way forward through the complications and the mess: friendship. The words &quot;freedom&quot; and &quot;friend&quot; come from the same root, the Proto-Indo-European &quot;pr&#299;-&quot;, meaning &quot;to love&quot;. It is love and friendship that allows us to navigate the complex ways that we depend on each other, without turning dependency into coercion&#8212;in other words, without turning our efforts to achieve positive liberties into violations of negative liberty.

This talk focuses on a particular conceptualization of friendship from relational psychology, called &quot;intersubjectivity&quot;. We will discuss what intersubjectivity is, how it helps protect us from coercion and enables us to flourish, and how we can practice intersubjectivity within FOSS projects and within all our communities.</description>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://program.foss-backstage.de/fossback26/talk/BQPCUJ/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
