Loading…
May 10-12, 2023
Vancouver, British Columbia, Canada + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Thursday, May 11 • 11:00am - 11:40am
The Importance of Developer Tooling to Make Open Source More Secure by Default - Brian Behlendorf, Open Source Security Foundation (OpenSSF)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
One important aspect of the Open Source Software (OSS) community’s collective security response should be to create developer tooling. Such tooling makes it easier to write secure software by default and reduces the burden on maintainers. Research by the OpenSSF and Linux Foundation have shown that maintainers often benefit from better developer tooling, particularly when they might not otherwise have bandwidth to focus on security. Examples include CI pipeline tooling, tools such as Sigstore for package signing and verification, and efforts such as automated vulnerability scans and remediation. Part of the OpenSSF’s Alpha-Omega Project, “Omega”, also works on applying automated security analysis, scoring, and remediation guidance to maintainer communities of the “long tail” of open source projects. There is a lot of potential for the community to improve this as a whole: for example, we could create CI tools to make it easier to integrate fuzzers or static analysis tools into pipelines. This session will discuss existing initiatives in this space and ideas for potential future directions of security tooling, as well as ways to get involved in these projects.

Speakers
avatar for Brian Behlendorf

Brian Behlendorf

Chief Technology Officer, Open Wallet Foundation
Brian has served most recently as General Manager and CTO of the Open Source Security Foundation (OpenSSF), has served as Executive Director of Hyperledger, and formerly as CTO of the World Economic Forum. He currently serves on the boards of the Electronic Frontier Foundation (EFF... Read More →


Thursday May 11, 2023 11:00am - 11:40am PDT
121 (Level 1)