In this interview from KubeCon + CloudNativeCon EU, Christopher "CRob" Robinson, CTO of the Open Source Security Foundation (OpenSSF), joins Greg Kroah-Hartman, Linux kernel maintainer, to talk with theCUBE's Rob Strechay and Paul Nashawaty about how the explosion of AI-generated bug reports is reshaping open source security — and the major industry coalition mobilizing to address it. Robinson details a new OpenSSF initiative backed by Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft and OpenAI to secure the rapidly expanding AI ecosystem. Kroah-Hartman reveals that after months of obvious "AI slop," a recent shift in tool quality means maintainers are now receiving legitimate AI-generated vulnerability reports, creating an unprecedented volume of work for core infrastructure projects. The new funding aims to provide developers with token credits, integrated tooling and AI-assisted triage to manage the flood.
The conversation also explores the European Cyber Resilience Act, which requires manufacturers to perform vulnerability management and ship software bills of materials starting September 2025. Kroah-Hartman explains how OpenSSF's best practices badge gives downstream companies a reliable signal that an open source project meets security and compliance standards — a critical differentiator as regulatory pressure intensifies. Robinson highlights how the convergence of CRA compliance obligations and AI-accelerated discovery could overwhelm maintainers with thousands of duplicate patches from organizations facing severe financial penalties. OpenSSF is responding on multiple fronts, from publishing an MLSecOps white paper and launching a free class on secure vibe coding to designing AI-powered advisors that consolidate similar pull requests and surface the strongest candidates for review. From educating upstream developers on identity, access and data handling fundamentals to helping enterprises avoid the security pitfalls of rushing agentic AI into production, the discussion underscores why open source governance must evolve at the same velocity as the tools reshaping it.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
KubeCon + CloudNativeCon EU 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for KubeCon EU 2026
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for KubeCon EU 2026.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
KubeCon + CloudNativeCon EU 2026. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to KubeCon + CloudNativeCon EU 2026
Please sign in with LinkedIn to continue to KubeCon + CloudNativeCon EU 2026. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Christopher "CRob" Robinson, OpenSSF & Greg Kroah-Hartman, The Linux Foundation
Rebecca Knight and Rob Strechay host a conversation with Christopher Robinson, CTO, OpenSSF, Greg Kroah-Harman, Linux Kernel Developer, Linux Foundation as part of theCUBE’s coverage of Kubecon + CloudNativeCon EU 2026 from Amsterdam, Netherlands
Christopher "CRob" Robinson, OpenSSF & Greg Kroah-Hartman, The Linux Foundation
CRob Robinson
CTOOpenSSF
Greg Kroah-Hartman
The Linux Foundation
In this interview from KubeCon + CloudNativeCon EU, Christopher "CRob" Robinson, CTO of the Open Source Security Foundation (OpenSSF), joins Greg Kroah-Hartman, Linux kernel maintainer, to talk with theCUBE's Rob Strechay and Paul Nashawaty about how the explosion of AI-generated bug reports is reshaping open source security — and the major industry coalition mobilizing to address it. Robinson details a new OpenSSF initiative backed by Anthropic, AWS, GitHub, Google, Google DeepMind, Microsoft and OpenAI to secure the rapidly expanding AI ecosystem. Kroah-Har...Read more