当前位置:网站首页>"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
2022-07-07 13:35:00 【Open source society】


| edit : Tanglingbo
| Coordinating editor : Wang Yuemin
| Design : Wang Fuzheng
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress
Google And other giants invested heavily in safety related , Including bug fixes
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc
Such a cutting-edge and important topic , We believe that more people should know and pay attention to it . from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 Issue 11 , We invite technical experts from Huawei open source management center , The open atom Foundation TOC Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .
This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?
Share time
7 month 5 Japan 19:00-20:30
Live broadcast platform and address
Sharing guests
Xu Liang
Huawei open source management center , The open atom Foundation TOC、OpenSSF Director of the foundation
Xue Guo
Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Protect Dangerous cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .
Ma Jinghe ( Little horse elder brother )
Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Tang Xiaoyin ( host )
CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey of Chinese developers Sue 》, Editor in chief 《 China AI Application developer Report 》、《 Open source applications in China Sender report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Click below Reservation live broadcast ,
Participate in interaction and win gifts
Related reading | Related Reading
The book of night and sky #53 Apache Of the open source community “ Stone soup ”
Investment promotion was fully launched | 2022 International Open Source Festival (IOSF) We send you an invitation to cooperate !

This article is from WeChat official account. - Kaiyuan society KAIYUANSHE(kaiyuanshe).
If there is any infringement , Please contact the [email protected] Delete .
Participation of this paper “OSC Source creation plan ”, You are welcome to join us , share .
边栏推荐
- Enregistrement de la navigation et de la mise en service du robot ROS intérieur (expérience de sélection du rayon de dilatation)
- How to make the new window opened by electorn on the window taskbar
- 为租客提供帮助
- Detr introduction
- QQ medicine, Tencent ticket
- MongoDB复制(副本集)总结
- Mongodb command summary
- PAcP learning note 3: pcap method description
- Scripy tutorial classic practice [New Concept English]
- Server to server (S2S) event (adjust)
猜你喜欢

Redis只能做缓存?太out了!

ESP32构解工程添加组件

Talk about pseudo sharing

Cmake learning and use notes (1)

Fast development board pinctrl and GPIO subsystem experiment for itop-imx6ull - modify the device tree file

Ogre introduction

如何让join跑得更快?

交付效率提升52倍,运营效率提升10倍,看《金融云原生技术实践案例汇编》(附下载)

How to make join run faster?

MongoDB内部的存储原理
随机推荐
PAcP learning note 1: programming with pcap
648. 单词替换 : 字典树的经典运用
xshell连接服务器把密钥登陆改为密码登陆
OSI seven layer model
Ogre introduction
Japanese government and enterprise employees got drunk and lost 460000 information USB flash drives. They publicly apologized and disclosed password rules
Simple and easy-to-use code specification
Detr introduction
C语言数组相关问题深度理解
Cmake learning and use notes (1)
What parameters need to be reconfigured to replace the new radar of ROS robot
Navicat运行sql文件导入数据不全或导入失败
JS function 返回多个值
[QNX Hypervisor 2.2用户手册]6.3.4 虚拟寄存器(guest_shm.h)
MongoDB的用户管理总结
Storage principle inside mongodb
LIS longest ascending subsequence problem (dynamic programming, greed + dichotomy)
centso7 openssl 报错Verify return code: 20 (unable to get local issuer certificate)
RealBasicVSR测试图片、视频
SSRF漏洞file伪协议之[网鼎杯 2018]Fakebook1






