Driving Security at Scale: Principles for Package Repository Security - Lecture
Offered By: OpenSSF via YouTube
Course Description
Overview
Explore the principles of package repository security in this 19-minute conference talk by Jack Cable from CISA and Zach Steindler from GitHub. Learn about the collaborative effort between CISA and the OpenSSF Securing Software Repositories Working Group to develop the "Principles for Package Repository Security" - an opinionated security maturity model with four levels. Understand how this voluntary framework helps package repositories evaluate their current security capabilities and plan their security roadmap. Discover how this initiative aligns with CISA's Open Source Software Security Roadmap and the White House's National Cybersecurity Strategy. Gain insights into the content of the maturity model, the process of its development, and learn how to effectively engage with CISA and open source package repositories to enhance security across open source ecosystems.
Syllabus
Driving Security at Scale: Principles for Package Repository Security - Jack Cable & Zach Steindler
Taught by
OpenSSF
Related Courses
Costs of Coding to ComplianceOWASP Foundation via YouTube OWASP SAMM Project - Introduction to Software Assurance Maturity Model
OWASP Foundation via YouTube OWASP DSOMM Project - Introduction to DevSecOps Maturity Model
OWASP Foundation via YouTube OWASP Top 10 Maturity Categories for Security Champions
OWASP Foundation via YouTube OpenSAMM Best Practices - Lessons from the Trenches
OWASP Foundation via YouTube