21–27 Sept 2026
EuXFEL Lighthouse
Europe/Berlin timezone

Securing and Extending HDF5: Audit, Provenance, and Ecosystem Advances

Not scheduled
20m
EuXFEL Lighthouse

EuXFEL Lighthouse

Poster Metadata + Data Formats Poster Session & Reception

Speaker

M. Scot Breitenfeld (HDF Group)

Description

HDF5 is foundational to data acquisition, reduction, analysis, and archival at large-scale research facilities. Its deployment makes integrity, trustworthy extensibility, performance, and maintainability ecosystem concerns, not library-only concerns. This poster presents coordinated work across HDF5 SHINES, S2-D2, and IOWarp.

HDF5 SHINES has assessed the library, format, extensions, and software supply chain, producing a risk register and a vulnerability-disclosure process supported by a Product Security Incident Response Team and The HDF Group’s role as a CVE Numbering Authority. Machine-readable GNU poke specifications enable independent validation, diagnostics, and repair. S2-D2 complements this work with cryptographic verification of dynamically loaded plugins and research on fine-grained, tamper-evident provenance. Current development also includes internally multithreaded chunk I/O, TOML filter configuration, and agent-assisted HDF5 use and performance guidance.

A parallel release-engineering effort focuses on reproducible builds, signed artifacts, build provenance, SBOMs, clearer compatibility guidance, coordinated vulnerability handling, and security-focused patch releases. Collaboration with HDF5 package maintainers in Debian and Fedora, and with downstream projects such as h5py and netCDF-C, will align pre-release testing, supported configurations, release schedules, and security communication. Together, these efforts aim to shorten the path from upstream fixes to facility deployment and strengthen HDF5 as a secure, usable, and dependable foundation for facility software.

Authors

Gerd Heber (HDF Group) M. Scot Breitenfeld (HDF Group)

Presentation materials

There are no materials yet.