Flock to Fedora 2026

Jaroslav Řezník

Jaroslav Řezník is a Principal Program Manager responsible for security standards and upcoming compliance activities under Red Hat's Product Security Compliance team. In his 18 years at Red Hat, he has touched many different areas from very different angles, from the community work on Fedora that is still his passion to compliance with government standards like Common Criteria and FIPS.


Matrix ID:

@rezza:matrix.org


Sessions

06-14
11:00
100min
Secure by Design: Aligning Fedora with the CRA
Jaroslav Řezník, Roman

What does "Secure Development" actually look like in a community-driven ecosystem? With the arrival of the EU Cyber Resilience Act (CRA), the industry is moving toward a more structured approach to software security. This hands-on workshop treats the CRA not as a hurdle, but as a baseline for excellence.

Designed for Fedora maintainers and developers, we’ll start with a practical "Intro to Secure Development," covering the core pillars of writing and maintaining resilient software. It will include an overview of existing security standards and tools specifically designed for open source and that already work.

We will then focus on mapping these practices to the CRA, showing how community projects can stay compliant through good engineering rather than paperwork. We will explore different options where stewards (like Red Hat) are supposed to step up and help, and how to get maximum value out of this collaboration.

We’ll look at the Fedora stack and explore how our existing processes, tools and pipelines can automate security requirements.

General
Topaz + Quartz
06-15
14:30
55min
The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Jaroslav Řezník, Roman

The European Union's Cyber Resilience Act (CRA) is the first "horizontal" law to formally recognize the role of open source in the commercial software supply chain. While any new regulation at this scale naturally brings questions, the CRA actually offers an opportunity to standardize and elevate security across the entire industry. The law also promotes collaboration between all FOSS ecosystem players - contributors, maintainers, foundations and commercial companies - by introducing the new role of steward. This session is an introduction into what the CRA really means for the community (spoiler - don’t be scared, you’re safe!) and how the true responsible stewards like Red Hat can help..

In the first part, we’re going to strip away the jargon and explain exactly what the CRA is. We’ll cover the basics of the Act: who it applies to, what it asks for, and how it acknowledges the unique nature of open source. We’ll look at the specific exemptions designed to protect the "way we work," making it clear why individual contributors and community-led development remain in a safe, protected space.

The second half of the talk introduces a concept of the Open Source Steward, designed specifically to support community projects. We’ll discuss how Red Hat, as a steward for Fedora, takes on the responsibility for high-level security policies, vulnerability reporting, and coordination with authorities. Join us to learn how this partnership allows the Fedora community to keep innovating freely and preserve its unique culture, style and processes. Red Hat is here to help navigate the new regulatory requirements and improve the project's security posture to keep delivering the best quality Linux distribution to its users.

General
Topaz + Quartz