YoVDO

The Importance of Developer Tooling for Secure Open Source Software

Offered By: Linux Foundation via YouTube

Tags

Software Development Courses Cybersecurity Courses CI/CD Courses Vulnerability Scanning Courses Sigstore Courses Alpha-Omega Project Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the critical role of developer tooling in enhancing open source software security in this 43-minute conference talk by Brian Behlendorf from the Open Source Security Foundation (OpenSSF). Discover how creating effective developer tools can simplify the process of writing secure software and alleviate the burden on maintainers. Learn about research findings from OpenSSF and Linux Foundation highlighting the benefits of improved tooling for maintainers with limited bandwidth for security concerns. Examine examples of valuable tools, including CI pipeline solutions, Sigstore for package signing and verification, and automated vulnerability scans and remediation. Gain insights into the Alpha-Omega Project's "Omega" initiative, which focuses on applying automated security analysis, scoring, and remediation guidance to the "long tail" of open source projects. Explore potential community-driven improvements, such as developing CI tools for easier integration of fuzzers or static analysis tools. Delve into existing initiatives in the security tooling space, discuss ideas for future developments, and learn how to get involved in these crucial projects.

Syllabus

The Importance of Developer Tooling to Make Open Source More Secure by Default - Brian Behlendorf


Taught by

Linux Foundation

Tags

Related Courses

Securing Your Software Supply Chain with Sigstore
Linux Foundation via edX
Hands-on Introduction to Sigstore - Securing the Software Supply Chain
Rawkode Academy via YouTube
Protecting the World's Greatest Open Source Ecosystem with Sigstore
Devoxx via YouTube
PGP vs Sigstore - The Match at Maven Central
Devoxx via YouTube
Securing Your Infrastructure as Code Pipeline
Linux Foundation via YouTube