Brussels / 31 January & 1 February 2026

schedule

Package Management


09 10 11 12 13 14 15 16 17 18
Saturday A phishy case study
Current state of attestations in programming language ecosystems
Name resolution in package management systems - A reproducibility perspective
Package managers à la carte: A Formal Model of Dependency Resolution
Trust Nothing, Trace Everything: Auditing Package Builds at Scale with OSS Rebuild
PURL: From FOSDEM 2018 to international standard
Binary Dependencies: Identifying the Hidden Packages We All Depend On
The terrible economics of package registries and how to fix them
Package Management Learnings from Homebrew
Event Speakers Start End

Saturday

  A phishy case study
Adam Harvey 10:30 10:55
  Current state of attestations in programming language ecosystems
Zach Steindler 11:00 11:25
  Name resolution in package management systems - A reproducibility perspective
Gábor Boskovits 11:30 11:55
  Package managers à la carte: A Formal Model of Dependency Resolution
Ryan Gibb 12:00 12:25
  Trust Nothing, Trace Everything: Auditing Package Builds at Scale with OSS Rebuild
Matthew Suozzo 12:30 12:55
  PURL: From FOSDEM 2018 to international standard
Philippe Ombredanne 13:00 13:10
  Binary Dependencies: Identifying the Hidden Packages We All Depend On
Vlad-Stefan Harbuz 13:15 13:25
  The terrible economics of package registries and how to fix them
Michael Winser 13:30 13:55
  Package Management Learnings from Homebrew
Mike McQuaid 14:00 14:25