当前位置:网站首页>"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?

"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?

2022-07-07 13:35:00 Open source society



|  edit : Tanglingbo

| Coordinating editor : Wang Yuemin

| Design : Wang Fuzheng


2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :

  • The China Academy of communications and communications was established “ Open source and security ” department

  • OpenSSF GM Brian Behlendorf Make a statement in the United States Congress

  • Google And other giants invested heavily in safety related , Including bug fixes

  • Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc


Such a cutting-edge and important topic , We believe that more people should know and pay attention to it . from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 Issue 11 , We invite technical experts from Huawei open source management center , The open atom Foundation TOC Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications  , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues . 


 

This topic


  • “ Open source security ” What does it mean in a general sense ?


  • Why does a small open source vulnerability lead to a very serious open source security problem ?


  • Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?


  • How should enterprises establish their own open source security strategy ?


 

 

Share time


7 month 5 Japan 19:00-20:30

 

Live broadcast platform and address

 
Broadcast address :https://live.csdn.net/room/csdnnews/fXXyTo5y
platform :CSDN Website 、CSDN Wechat video Number


Sharing guests

Xu Liang

Huawei open source management center , The open atom Foundation TOC、OpenSSF Director of the foundation


As a member of the open source community, it is close 10 year , Experienced in the open source community “90 after ”, Xu Liang has been involved in the open source community since high school ,2011 It has become Debian Developers of , And repeatedly undertake GSoC Project mentors . Now he is a technical expert of Huawei open source capability center 、 Open atom open source foundation TOC member .



Xue Guo

Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications


Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Protect Dangerous cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .



Ma Jinghe ( Little horse elder brother )

Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group


Engaged in research and development (ZTE), Have practiced DevSecOps(IBM), Currently in Jihu (GitLab) do DevOps/DevSecOps Technical sermons . Participate in open source related activities in your spare time , yes LFAPAC Open source preacher ,CDF ambassador,OpenSSF Deputy head of China Working Group .


Tang Xiaoyin  ( host )

CSDN《 New programmers 》 Managing editor


Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey of Chinese developers Sue 》, Editor in chief 《 China AI Application developer Report 》、《 Open source applications in China Sender report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .

  Click below Reservation live broadcast ,

Participate in interaction and win gifts




Related reading | Related Reading


The book of night and sky #53 Apache Of the open source community “ Stone soup ”

Investment promotion was fully launched | 2022 International Open Source Festival (IOSF) We send you an invitation to cooperate !

The first technology podcast month is about to begin


Introduction to Kaiyuan society

Kaiyuan society was founded in 2014 year , It's made up of individual members who volunteer to contribute to the cause of open source , In accordance with the “ contribution 、 Consensus 、 Co governance ” Composed of principles , Always maintain vendor neutrality 、 public welfare 、 The characteristics of non-profit , It was the first to “ Open source governance 、 International connection 、 Community development 、 Open source project ” Open source community Consortium for mission . Open source community actively supports open source community 、 Enterprises and relevant government units work closely together , With “ Based on China 、 Contribute to the world ” For the vision , It aims to create a healthy and sustainable open source ecosystem , Promote China's open source community to become an active participant and contributor to the global open source system .


2017 year , The open source society has transformed into a completely composed of individual members , reference ASF And other international top open source foundations . In the last eight years , It links tens of thousands of open source people , Gathered thousands of community members and volunteers 、 Hundreds of lecturers at home and abroad , It has cooperated with nearly 100 sponsors 、 The media 、 Community partners .





This article is from WeChat official account. - Kaiyuan society KAIYUANSHE(kaiyuanshe).
If there is any infringement , Please contact the [email protected] Delete .
Participation of this paper “OSC Source creation plan ”, You are welcome to join us , share .

原网站

版权声明
本文为[Open source society]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/188/202207071050461372.html