The Current State of Open Source Security Compliance Tooling Is Well, Sad
Offered By: OpenSSF via YouTube
Course Description
Overview
Explore the challenges and practical solutions for open source security compliance in this 18-minute conference talk by Philippe Ombredanne from AboutCode. Gain insights into the limitations of proprietary tools in addressing software supply chain issues and meeting regulatory requirements. Learn about the struggles faced by software teams in navigating the complex landscape of security tools and databases, especially in light of the increasing number of reported CVEs. Discover practical approaches using OpenSSF projects, open source tools, and open data to achieve automated compliance and robust software supply chain security processes.
Syllabus
The Current State of Open Source Security Compliance Tooling Is … Well, Sad. - Philippe Ombredanne
Taught by
OpenSSF
Related Courses
Security Is an Ecosystem - We Can't Be Secure in IsolationLinux Foundation via YouTube Improving the Security of a Large Open Source Project One Step at a Time
Linux Foundation via YouTube Simplifying Coordinating Vulnerabilities and Disclosures in Open Source Projects
Linux Foundation via YouTube SLSA in Action: Securing the Software Supply Chain
Linux Foundation via YouTube Implementing OpenSSF Best Practices Badges and Scorecards for Project Security
Linux Foundation via YouTube