Flock to Fedora 2026

Secure by Design: Aligning Fedora with the CRA
2026-06-14 , Topaz + Quartz

What does "Secure Development" actually look like in a community-driven ecosystem? With the arrival of the EU Cyber Resilience Act (CRA), the industry is moving toward a more structured approach to software security. This hands-on workshop treats the CRA not as a hurdle, but as a baseline for excellence.

Designed for Fedora maintainers and developers, we’ll start with a practical "Intro to Secure Development," covering the core pillars of writing and maintaining resilient software. It will include an overview of existing security standards and tools specifically designed for open source and that already work.

We will then focus on mapping these practices to the CRA, showing how community projects can stay compliant through good engineering rather than paperwork. We will explore different options where stewards (like Red Hat) are supposed to step up and help, and how to get maximum value out of this collaboration.

We’ll look at the Fedora stack and explore how our existing processes, tools and pipelines can automate security requirements.

See also: Slides (2.6 MB)

Jaroslav Řezník is a Principal Program Manager responsible for security standards and upcoming compliance activities under Red Hat's Product Security Compliance team. In his 18 years at Red Hat, he has touched many different areas from very different angles, from the community work on Fedora that is still his passion to compliance with government standards like Common Criteria and FIPS.

This speaker also appears in:

Roman is a cybersecurity expert, engineer, and leader with over 18 years of hands-on experience securing complex systems and products at scale. At Red Hat Roman leads open-source security strategy, upstream collaboration, and cross-industry initiatives focused on building trusted ecosystems. He has built and scaled programs across security architecture, threat modeling, secure development, vulnerability management, incident response, and security education - for both engineers and senior leadership. His work spans trusted AI, privacy, compliance, and secure software supply chains. Previously, Roman led Product Security & Privacy for Data Center and AI software at Intel. He is a Security Champion for several open-source projects and an active contributor to working groups under the OpenSSF, Eclipse Foundation, and other global initiatives. He is an official member of CEN/CLC and ETSI standardization groups, contributing to the EU Cyber Resilience Act (CRA).

This speaker also appears in: