当前位置:网站首页>Open source and safe "song of ice and fire"
Open source and safe "song of ice and fire"
2022-07-06 17:51:00 【CSDN information】

author | He Miao Coordinating editor | Zhang Hongyue
Produce | CSDN(ID:CSDNnews)
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department ;
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress ;
Google And other giants invested heavily in safety related , Including bug fixes ;
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc .
Such a cutting-edge and important topic , More people should know and pay attention to . therefore , from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 In the eleventh issue, we invited technical experts from Huawei open source management center , The open atom Foundation TOC Member Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .


This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?

Share time and address
Time :7 month 5 Japan 19:00-20:30
Broadcast address :https://live.csdn.net/room/csdnnews/fXXyTo5y
platform :CSDN Website 、CSDN Wechat video Number

Sharing guests

Xu Liang Huawei open source management center , The open atom Foundation TOC member
As a member of the open source community, it is close 10 year , Experienced in the open source community “90 after ”, Xu Liang has been involved in the open source community since high school ,2011 It has become Debian Developers of , And repeatedly undertake GSoC Project mentors . Now he is a technical expert of Huawei open source capability center 、 Open atom open source foundation TOC member .

Xue Guo Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Xue Guo , Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications . Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Insurance cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .

Ma Jinghe Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Engaged in research and development (ZTE), Have practiced DevSecOps(IBM), Currently in Jihu (GitLab) do DevOps/DevSecOps Technical sermons . Participate in open source related activities in your spare time , yes LFAPAC Open source preacher ,CDF ambassador,OpenSSF Deputy head of China Working Group .

Tang Xiaoyin ( host )CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey report of Chinese developers 》, Editor in chief 《 China AI Application developer Report 》、《 China open source application developer report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Scan QR code to make an appointment for live broadcast
Participate in interaction and win gifts

边栏推荐
- 10 advanced concepts that must be understood in learning SQL
- Run xv6 system
- 李書福為何要親自掛帥造手機?
- Fleet tutorial 13 basic introduction to listview's most commonly used scroll controls (tutorial includes source code)
- Today in history: the mother of Google was born; Two Turing Award pioneers born on the same day
- node の SQLite
- How to solve the error "press any to exit" when deploying multiple easycvr on one server?
- Pyspark operator processing spatial data full parsing (5): how to use spatial operation interface in pyspark
- Xin'an Second Edition: Chapter 26 big data security demand analysis and security protection engineering learning notes
- How to output special symbols in shell
猜你喜欢

Unity小技巧 - 绘制瞄准准心

scratch疫情隔离和核酸检测模拟 电子学会图形化编程scratch等级考试三级真题和答案解析2022年6月

【Elastic】Elastic缺少xpack无法创建模板 unknown setting index.lifecycle.name index.lifecycle.rollover_alias

Video fusion cloud platform easycvr adds multi-level grouping, which can flexibly manage access devices

EasyCVR电子地图中设备播放器loading样式的居中对齐优化

李書福為何要親自掛帥造手機?

node の SQLite

面试突击62:group by 有哪些注意事项?
![[getting started with MySQL] fourth, explore operators in MySQL with Kiko](/img/11/66b4908ed8f253d599942f35bde96a.png)
[getting started with MySQL] fourth, explore operators in MySQL with Kiko

EasyCVR接入设备开启音频后,视频无法正常播放是什么原因?
随机推荐
学 SQL 必须了解的 10 个高级概念
PySpark算子处理空间数据全解析(5): 如何在PySpark里面使用空间运算接口
Interview assault 63: how to remove duplication in MySQL?
node の SQLite
The art of Engineering (2): the transformation from general type to specific type needs to be tested for legitimacy
MySQL stored procedure
Unity小技巧 - 绘制瞄准准心
RepPoints:可形变卷积的进阶
Remote code execution penetration test - B module test
MySQL 8 sub database and table backup database shell script
VR全景婚礼,帮助新人记录浪漫且美好的场景
Establishment of graphical monitoring grafana
Getting started with pytest ----- allow generate report
C# NanoFramework 点灯和按键 之 ESP32
【MySQL入门】第四话 · 和kiko一起探索MySQL中的运算符
Today in history: the mother of Google was born; Two Turing Award pioneers born on the same day
Single responsibility principle
Automatic operation and maintenance sharp weapon ansible Foundation
编译原理——预测表C语言实现
EasyCVR接入设备开启音频后,视频无法正常播放是什么原因?