当前位置:网站首页>"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
"Song of ice and fire" in the eleventh issue of "open source Roundtable" -- how to balance the natural contradiction between open source and security?
2022-07-07 13:35:00 【Open source society】


| edit : Tanglingbo
| Coordinating editor : Wang Yuemin
| Design : Wang Fuzheng
2022 Open a year log4j Cause the global information security earthquake , Governments around the world 、 Non profit foundations 、 Think tanks are paying high attention to the field of open source security :
The China Academy of communications and communications was established “ Open source and security ” department
OpenSSF GM Brian Behlendorf Make a statement in the United States Congress
Google And other giants invested heavily in safety related , Including bug fixes
Open source occupies more of the software supply chain , Enterprises begin to pay attention to SBOM、 Compliance testing, etc
Such a cutting-edge and important topic , We believe that more people should know and pay attention to it . from CSDN The host , Yunda Institute of China Academy of information and communication 、 Kaiyuan society 、 Tengyuan Association jointly supports 《 Open source Roundtable 》 Issue 11 , We invite technical experts from Huawei open source management center , The open atom Foundation TOC Xu Liang , Guoxue, deputy director of open source and software security department of Yunda Institute of Chinese Academy of communications , Polar fox (GitLab) DevOps Technical preacher 、OpenSSF Ma Jinghe, deputy head of the China working group, jointly discussed open source security issues .
This topic
“ Open source security ” What does it mean in a general sense ?
Why does a small open source vulnerability lead to a very serious open source security problem ?
Open source usually means open , And a high degree of openness will also bring higher risks , How to balance the natural contradiction between open source and security ?
How should enterprises establish their own open source security strategy ?
Share time
7 month 5 Japan 19:00-20:30
Live broadcast platform and address
Sharing guests
Xu Liang
Huawei open source management center , The open atom Foundation TOC、OpenSSF Director of the foundation
Xue Guo
Deputy director of the open source and software security department of the Yunda Institute of the Chinese Academy of the communications
Mainly engaged in open source 、 Safety related work , At present, he is the director of China Communications Standardization Association TC608 Open source governance 、 Protect Dangerous cloud 、 Cloud security 、 Team leader of risk management and other working groups . Lead the preparation ITU standard 《 Cloud computing risk management framework 》, Establish a trusted open source standard system , Lead the preparation 《 Open source ecological white paper 》 And more than ten white papers on open source and security .
Ma Jinghe ( Little horse elder brother )
Polar fox (GitLab) DevOps Technical preacher ,OpenSSF Deputy head of China Working Group
Tang Xiaoyin ( host )
CSDN《 New programmers 》 Managing editor
Tang Xiaoyin ,CSDN《 New programmers 》 Managing editor , Plan as a whole 《 Annual survey of Chinese developers Sue 》, Editor in chief 《 China AI Application developer Report 》、《 Open source applications in China Sender report 》 Series report , primary 《 The programmer 》 Magazine editor , Previous appointment MDCC、CCAI、 Editor in chief of developer conferences such as the open source heroes Association .
Click below Reservation live broadcast ,
Participate in interaction and win gifts
Related reading | Related Reading
The book of night and sky #53 Apache Of the open source community “ Stone soup ”
Investment promotion was fully launched | 2022 International Open Source Festival (IOSF) We send you an invitation to cooperate !

This article is from WeChat official account. - Kaiyuan society KAIYUANSHE(kaiyuanshe).
If there is any infringement , Please contact the [email protected] Delete .
Participation of this paper “OSC Source creation plan ”, You are welcome to join us , share .
边栏推荐
猜你喜欢

Distributed transaction solution

Navicat run SQL file import data incomplete or import failed

【黑马早报】华为辟谣“军师”陈春花;恒驰5预售价17.9万元;周杰伦新专辑MV 3小时播放量破亿;法华寺回应万元月薪招人...

xshell连接服务器把密钥登陆改为密码登陆

实现IP地址归属地显示功能、号码归属地查询

Fast development board pinctrl and GPIO subsystem experiment for itop-imx6ull - modify the device tree file

Ways to improve the performance of raspberry pie

分布式事务解决方案

LIS 最长上升子序列问题(动态规划、贪心+二分)

Cinnamon 任务栏网速
随机推荐
User management summary of mongodb
Ways to improve the performance of raspberry pie
2022-7-6 Leetcode 977.有序数组的平方
MongoDB复制(副本集)总结
flask session伪造之hctf admin
记一次 .NET 某新能源系统 线程疯涨 分析
.net core 关于redis的pipeline以及事务
C语言数组相关问题深度理解
My "troublesome" subordinates after 00: not bad for money, against leaders, and resist overtime
MongoDB的导入导出、备份恢复总结
MongoDB 遇见 spark(进行整合)
ESP32构解工程添加组件
作战图鉴:12大场景详述容器安全建设要求
cmake 学习使用笔记(一)
[QNX Hypervisor 2.2用户手册]6.3.4 虚拟寄存器(guest_shm.h)
单片机原理期末复习笔记
【面试高频题】难度 2.5/5,简单结合 DFS 的 Trie 模板级运用题
How to make the new window opened by electorn on the window taskbar
Deep understanding of array related problems in C language
Signal strength (RSSI) knowledge sorting






