当前位置:网站首页>"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
2022-07-07 13:35:00 【Open source society】

| edit : Tanglingbo
| Coordinating editor : Wang Yuemin
| Design : Wang Fuzheng
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress
Google And other giants invested heavily in safety related , Including bug fixes
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc
Such a cutting-edge and important topic , We believe that more people should know and pay attention to it . from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 Issue 11 , We invite technical experts from Huawei open source management center , The open atom Foundation TOC Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .
This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?
Share time
7 month 5 Japan 19:00-20:30
Live broadcast platform and address
Sharing guests
Xu Liang
Huawei open source management center , The open atom Foundation TOC、OpenSSF Director of the foundation
Xue Guo
Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Protect Dangerous cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .
Ma Jinghe ( Little horse elder brother )
Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Tang Xiaoyin ( host )
CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey of Chinese developers Sue 》, Editor in chief 《 China AI Application developer Report 》、《 Open source applications in China Sender report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Click below Reservation live broadcast ,
Participate in interaction and win gifts
Related reading | Related Reading
The book of night and sky #53 Apache Of the open source community “ Stone soup ”
Investment promotion was fully launched | 2022 International Open Source Festival (IOSF) We send you an invitation to cooperate !

This article is from WeChat official account. - Kaiyuan society KAIYUANSHE(kaiyuanshe).
If there is any infringement , Please contact the [email protected] Delete .
Participation of this paper “OSC Source creation plan ”, You are welcome to join us , share .
边栏推荐
- move base参数解析及经验总结
- Read PG in data warehouse in one article_ stat
- Xshell connection server changes key login to password login
- 2022-7-6 使用SIGURG来接受外带数据,不知道为什么打印不出来
- Mongodb meets spark (for integration)
- Cinnamon taskbar speed
- error LNK2019: 无法解析的外部符号
- php——laravel缓存cache
- Error lnk2019: unresolved external symbol
- JS function 返回多个值
猜你喜欢
How far can it go to adopt a cow by selling the concept to the market?
[Presto profile series] timeline use
Introduce six open source protocols in detail (instructions for programmers)
Vscade editor esp32 header file wavy line does not jump completely solved
flask session伪造之hctf admin
存储过程的介绍与基本使用
Enregistrement de la navigation et de la mise en service du robot ROS intérieur (expérience de sélection du rayon de dilatation)
数据库系统概论-第一章绪论【概念模型、层次模型和三级模式(外模式、模式、内模式)】
室内ROS机器人导航调试记录(膨胀半径的选取经验)
Cinnamon 任务栏网速
随机推荐
Problems that cannot be accessed in MySQL LAN
Mongodb replication (replica set) summary
[learning notes] zkw segment tree
Ikvm of toolbox Net project new progress
MongoDB 遇见 spark(进行整合)
Why can basic data types call methods in JS
[1] Basic knowledge of ros2 - summary version of operation commands
Custom thread pool rejection policy
干货|总结那些漏洞工具的联动使用
[etc.] what are the security objectives and implementation methods that cloud computing security expansion requires to focus on?
数字ic设计——SPI
作战图鉴:12大场景详述容器安全建设要求
LeetCode简单题分享(20)
JS缓动动画原理教学(超细节)
RealBasicVSR测试图片、视频
最佳实践 | 用腾讯云AI意愿核身为电话合规保驾护航
Detr introduction
JS determines whether an object is empty
What parameters need to be reconfigured to replace the new radar of ROS robot
Data refresh of recyclerview