Flock to Fedora 2026

Roman

Roman is a cybersecurity expert, engineer, and leader with over 18 years of hands-on experience securing complex systems and products at scale. At Red Hat Roman leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education - for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).


Sessions

06-14
11:00
100min
Secure by Design: Aligning Fedora with the CRA
Jaroslav Řezník, Roman

What does "Secure Development" actually look like in a community-driven ecosystem? With the arrival of the EU Cyber Resilience Act (CRA), the industry is moving toward a more structured approach to software security. This hands-on workshop treats the CRA not as a hurdle, but as a baseline for excellence.

Designed for Fedora maintainers and developers, we’ll start with a practical "Intro to Secure Development," covering the core pillars of writing and maintaining resilient software. It will include an overview of existing security standards and tools specifically designed for open source and that already work.

We will then focus on mapping these practices to the CRA, showing how community projects can stay compliant through good engineering rather than paperwork. We will explore different options where stewards (like Red Hat) are supposed to step up and help, and how to get maximum value out of this collaboration.

We’ll look at the Fedora stack and explore how our existing processes, tools and pipelines can automate security requirements.

General
Topaz + Quartz
06-15
14:30
55min
The EU CRA vs. Community: Why You’re Safe, and How Stewards Help
Jaroslav Řezník, Roman

The European Union's Cyber Resilience Act (CRA) is the first "horizontal" law to formally recognize the role of open source in the commercial software supply chain. While any new regulation at this scale naturally brings questions, the CRA actually offers an opportunity to standardize and elevate security across the entire industry. The law also promotes collaboration between all FOSS ecosystem players - contributors, maintainers, foundations and commercial companies - by introducing the new role of steward. This session is an introduction into what the CRA really means for the community (spoiler - don’t be scared, you’re safe!) and how the true responsible stewards like Red Hat can help..

In the first part, we’re going to strip away the jargon and explain exactly what the CRA is. We’ll cover the basics of the Act: who it applies to, what it asks for, and how it acknowledges the unique nature of open source. We’ll look at the specific exemptions designed to protect the "way we work," making it clear why individual contributors and community-led development remain in a safe, protected space.

The second half of the talk introduces a concept of the Open Source Steward, designed specifically to support community projects. We’ll discuss how Red Hat, as a steward for Fedora, takes on the responsibility for high-level security policies, vulnerability reporting, and coordination with authorities. Join us to learn how this partnership allows the Fedora community to keep innovating freely and preserve its unique culture, style and processes. Red Hat is here to help navigate the new regulatory requirements and improve the project's security posture to keep delivering the best quality Linux distribution to its users.

General
Topaz + Quartz