How to Be a Good Citizen Contributor to Open Source in the Age of Regulation

Open source runs everything. But in 2026 the ecosystem that sustains it experiences, perhaps, the biggest simultaneous challenges in its history: maintainer burnout, chronic underfunding, regulatory pressure (e.g, from the EU Cyber Resilience Act), an AI-accelerated vulnerability tsunami, and a flood of AI-generated issues and PRs. Open source projects experience "enforced collaboration" that has led companies, researchers, everyone to shove pull requests and demand immediate response from the community, often lacking awareness of the diverse open source governance and contributing norms. This session outlines how people from companies and society can responsibly contribute back to open source while preserving upstream health. It highlights two OpenSSF initiatives. First, a Concise Guide for Upstream Collaboration, developed by the Best Practices WG and aiming to help OSPOs guide employees through security upstream contributions. Second, the deliverables of the Global Cyber Policy WG, including CRA Maintainer Guidance, demonstrating how community developers can establish clear consumption expectations, shielding them from unreasonable compliance pressure. Attendees will leave with a clear understanding of diverse upstream ecosystem operations and how to interact with and responsibly contribute to open source projects we all depend upon.
Roman Zhukov
Roman is a cybersecurity expert, engineer, and leader with 20 years of hands-on experience securing complex systems and products at scale. Currently Principal Architect at Red Hat, he leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education - for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).

