Back to Tracks

Open Source in the Agent Era

How open source communities, forges, and foundations survive and thrive when AI agents produce most contributions — and how trust is rebuilt around provenance.

Key Topics

AI-BOM: signed, verifiable records of who — human or AI — wrote the code

Provenance and supply-chain trust (SPDX, SLSA, in-toto)

Maintainer sustainability under AI-generated contribution floods

Forge-independent trust: GitHub, Gitea, Forgejo and beyond

The economics of open source when code is abundant

Foundations and consortia: governance for the agent era

Key Question

When agents write most code, what must open source communities change to stay trustworthy? This track gathers forge maintainers, foundation leaders, supply-chain security experts, and independent maintainers.

Working Output

  • Draft charter for an ecosystem working group
  • A shared position on AI-BOM and provenance standards
  • Recommendations for maintainer sustainability

Interested in this track?

Request an invitation to join the conversation

Request Invitation