How open source communities, forges, and foundations survive and thrive when AI agents produce most contributions — and how trust is rebuilt around provenance.
AI-BOM: signed, verifiable records of who — human or AI — wrote the code
Provenance and supply-chain trust (SPDX, SLSA, in-toto)
Maintainer sustainability under AI-generated contribution floods
Forge-independent trust: GitHub, Gitea, Forgejo and beyond
The economics of open source when code is abundant
Foundations and consortia: governance for the agent era
When agents write most code, what must open source communities change to stay trustworthy? This track gathers forge maintainers, foundation leaders, supply-chain security experts, and independent maintainers.