Loading…
May 10-12, 2023
Vancouver, British Columbia, Canada + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Thursday, May 11 • 4:05pm - 4:45pm
Configuration as a Code: Managing Hundreds of GitHub Organizations to Streamline Supply Chain Security - Mikaël Barbero, Eclipse Foundation

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
How to make sure that the configuration of hundreds of GitHub projects of the Eclipse Foundation stays secure and coherent? This story starts when the OpenSSF Alpha-Omega initiative has enabled the Eclipse Foundation to invest in improving the software security chain for its projects. We ran the OpenSSF Scorecard project and identified some recurrent misconfigurations. But managing numerous organizations and repositories creates challenges. This evaluation with Scorecard shows an urgent need for a tool to effectively manage and rectify misconfigurations in our 1000+ repositories. To tackle this challenge, we are introducing a "configuration as code" solution for managing multiple GitHub organizations. This approach automates many tasks involved in maintaining a secure and consistent supply chain, reducing security vulnerability risk, and increasing project trust. “Configuration as code” provides visibility into security settings and the ability to make configuration changes through a familiar pull-request process. Participants will learn about the tools and techniques we employed in our organization and how they can be adapted for their own purposes.

Speakers
avatar for Mikaël Barbero

Mikaël Barbero

Head of Security, Eclipse Foundation
Mikaël is passionate for software engineering. He enjoys building user-centered software and solutions. His experience is diverse and includes things from architecture to team management. He started programming at the age of 8 in ST Basic and hasn't stopped ever since (he changed... Read More →



Thursday May 11, 2023 4:05pm - 4:45pm PDT
122 (Level 1)