当前位置:网站首页>Open source and safe "song of ice and fire"
Open source and safe "song of ice and fire"
2022-07-06 17:51:00 【CSDN information】

author | He Miao Coordinating editor | Zhang Hongyue
Produce | CSDN(ID:CSDNnews)
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department ;
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress ;
Google And other giants invested heavily in safety related , Including bug fixes ;
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc .
Such a cutting-edge and important topic , More people should know and pay attention to . therefore , from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 In the eleventh issue, we invited technical experts from Huawei open source management center , The open atom Foundation TOC Member Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .


This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?

Share time and address
Time :7 month 5 Japan 19:00-20:30
Broadcast address :https://live.csdn.net/room/csdnnews/fXXyTo5y
platform :CSDN Website 、CSDN Wechat video Number

Sharing guests

Xu Liang Huawei open source management center , The open atom Foundation TOC member
As a member of the open source community, it is close 10 year , Experienced in the open source community “90 after ”, Xu Liang has been involved in the open source community since high school ,2011 It has become Debian Developers of , And repeatedly undertake GSoC Project mentors . Now he is a technical expert of Huawei open source capability center 、 Open atom open source foundation TOC member .

Xue Guo Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Xue Guo , Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications . Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Insurance cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .

Ma Jinghe Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Engaged in research and development (ZTE), Have practiced DevSecOps(IBM), Currently in Jihu (GitLab) do DevOps/DevSecOps Technical sermons . Participate in open source related activities in your spare time , yes LFAPAC Open source preacher ,CDF ambassador,OpenSSF Deputy head of China Working Group .

Tang Xiaoyin ( host )CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey report of Chinese developers 》, Editor in chief 《 China AI Application developer Report 》、《 China open source application developer report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Scan QR code to make an appointment for live broadcast
Participate in interaction and win gifts

边栏推荐
- 基本磁盘与动态磁盘 RAID磁盘冗余阵列区分
- Growth of operation and maintenance Xiaobai - week 7
- 遠程代碼執行滲透測試——B模塊測試
- Essai de pénétration du Code à distance - essai du module b
- 远程代码执行渗透测试——B模块测试
- C语言指针*p++、*(p++)、*++p、*(++p)、(*p)++、++(*p)对比实例
- 面试突击62:group by 有哪些注意事项?
- [introduction to MySQL] third, common data types in MySQL
- Manifest of SAP ui5 framework json
- 重磅硬核 | 一文聊透对象在 JVM 中的内存布局,以及内存对齐和压缩指针的原理及应用
猜你喜欢

Selected technical experts from China Mobile, ant, SF, and Xingsheng will show you the guarantee of architecture stability

Spark calculation operator and some small details in liunx

Unity particle special effects series - treasure chest of shining stars

Optimization of middle alignment of loading style of device player in easycvr electronic map

Smart street lamp based on stm32+ Huawei cloud IOT design

【Elastic】Elastic缺少xpack无法创建模板 unknown setting index.lifecycle.name index.lifecycle.rollover_alias

Kivy tutorial: support Chinese in Kivy to build cross platform applications (tutorial includes source code)

The NTFS format converter (convert.exe) is missing from the current system

78 岁华科教授逐梦 40 载,国产数据库达梦冲刺 IPO

重磅!蚂蚁开源可信隐私计算框架“隐语”,主流技术灵活组装、开发者友好分层设计...
随机推荐
Zen integration nails, bugs, needs, etc. are reminded by nails
历史上的今天:Google 之母出生;同一天诞生的两位图灵奖先驱
The integrated real-time HTAP database stonedb, how to replace MySQL and achieve nearly a hundredfold performance improvement
Selected technical experts from China Mobile, ant, SF, and Xingsheng will show you the guarantee of architecture stability
OliveTin能在网页上安全运行shell命令(上)
酷雷曼多种AI数字人形象,打造科技感VR虚拟展厅
分布式(一致性协议)之领导人选举( DotNext.Net.Cluster 实现Raft 选举 )
TCP connection is more than communicating with TCP protocol
Basic configuration and use of spark
The art of Engineering (1): try to package things that do not need to be exposed
Getting started with pytest ----- allow generate report
远程代码执行渗透测试——B模块测试
Stealing others' vulnerability reports and selling them into sidelines, and the vulnerability reward platform gives rise to "insiders"
Openharmony developer documentation open source project
node の SQLite
Unity小技巧 - 绘制瞄准准心
Easy introduction to SQL (1): addition, deletion, modification and simple query
Interview assault 63: how to remove duplication in MySQL?
BearPi-HM_ Nano development environment
重磅!蚂蚁开源可信隐私计算框架“隐语”,主流技术灵活组装、开发者友好分层设计...