当前位置:网站首页>"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
2022-07-07 13:35:00 【Open source society】

| edit : Tanglingbo
| Coordinating editor : Wang Yuemin
| Design : Wang Fuzheng
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress
Google And other giants invested heavily in safety related , Including bug fixes
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc
Such a cutting-edge and important topic , We believe that more people should know and pay attention to it . from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 Issue 11 , We invite technical experts from Huawei open source management center , The open atom Foundation TOC Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .
This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?
Share time
7 month 5 Japan 19:00-20:30
Live broadcast platform and address
Sharing guests
Xu Liang
Huawei open source management center , The open atom Foundation TOC、OpenSSF Director of the foundation
Xue Guo
Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Protect Dangerous cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .
Ma Jinghe ( Little horse elder brother )
Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Tang Xiaoyin ( host )
CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey of Chinese developers Sue 》, Editor in chief 《 China AI Application developer Report 》、《 Open source applications in China Sender report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Click below Reservation live broadcast ,
Participate in interaction and win gifts
Related reading | Related Reading
The book of night and sky #53 Apache Of the open source community “ Stone soup ”
Investment promotion was fully launched | 2022 International Open Source Festival (IOSF) We send you an invitation to cooperate !

This article is from WeChat official account. - Kaiyuan society KAIYUANSHE(kaiyuanshe).
If there is any infringement , Please contact the [email protected] Delete .
Participation of this paper “OSC Source creation plan ”, You are welcome to join us , share .
边栏推荐
- Simple and easy-to-use code specification
- Flink | 多流转换
- 分屏bug 小记
- [1] Basic knowledge of ros2 - summary version of operation commands
- JS缓动动画原理教学(超细节)
- Write it down once Net a new energy system thread surge analysis
- Mongodb command summary
- 作战图鉴:12大场景详述容器安全建设要求
- centso7 openssl 报错Verify return code: 20 (unable to get local issuer certificate)
- Storage principle inside mongodb
猜你喜欢
Vscade editor esp32 header file wavy line does not jump completely solved
Thread pool reject policy best practices
Japanese government and enterprise employees got drunk and lost 460000 information USB flash drives. They publicly apologized and disclosed password rules
高端了8年,雅迪如今怎么样?
Detr introduction
1、深拷贝 2、call apply bind 3、for of for in 区别
Flink | multi stream conversion
118. 杨辉三角
How far can it go to adopt a cow by selling the concept to the market?
单片机学习笔记之点亮led 灯
随机推荐
2022-7-6 初学redis(一)在 Linux 下下载安装并运行 redis
Ikvm of toolbox Net project new progress
Talk about pseudo sharing
Cinnamon 任务栏网速
Getting started with MySQL
How did Guotai Junan Securities open an account? Is it safe to open an account?
LIS longest ascending subsequence problem (dynamic programming, greed + dichotomy)
Redis只能做缓存?太out了!
QQ的药,腾讯的票
OSI 七层模型
clion mingw64中文乱码
Pcap learning notes II: pcap4j source code Notes
MySQL error 28 and solution
Mongodb meets spark (for integration)
[learning notes] segment tree selection
MongoDB的用户管理总结
社会责任·价值共创,中关村网络安全与信息化产业联盟对话网信企业家海泰方圆董事长姜海舟先生
简单好用的代码规范
得物客服热线的演进之路
centso7 openssl 报错Verify return code: 20 (unable to get local issuer certificate)