#sosscommunity search results

OSV database — aims to be precise about versions affected, recommendations about whether you’re vulnerable, and allow for automations. For example, log4j is 6 levels deep, and all 6 levels need to be patched. Versus something surface level Prioritize by impact. #SOSSCommunity

webchick's tweet image. OSV database — aims to be precise about versions affected, recommendations about whether you’re vulnerable, and allow for automations.

For example, log4j is 6 levels deep, and all 6 levels need to be patched. Versus something surface level

Prioritize by impact.

#SOSSCommunity

And thanks to @ramiyengar for being the glue that binds the whole openSSF india. #SOSSCommunity

dhamijaabhi's tweet image. And thanks to @ramiyengar for being the glue that binds the whole openSSF india.  #SOSSCommunity

Every time a high-profile incident happens in #OpenSource, it shakes confidence. How do we respond? @OpenSSF tries to solve this issue, but we all need to engage. *Take responsibility for software you’re using.* “The community” won’t fix it. (Free as in puppy.) #SOSSCommunity

webchick's tweet image. Every time a high-profile incident happens in #OpenSource, it shakes confidence. How do we respond?

@OpenSSF tries to solve this issue, but we all need to engage.

*Take responsibility for software you’re using.* “The community” won’t fix it. (Free as in puppy.)

#SOSSCommunity

Today is the day! @webchick @KatherineD @tabdido and I take the #sosscommunity day stage Connecting Supply Chain Security Projects to the Community - Exploring OpenSSF’s DevRel Mission #ossummit

LoriLorusso's tweet image. Today is the day! @webchick @KatherineD @tabdido and I take the #sosscommunity day stage Connecting Supply Chain Security Projects to the Community - Exploring OpenSSF’s DevRel Mission #ossummit

At Open Source Summit ⁦@linuxfoundation#OSSummit this week and today at @OpenSSF’s #SOSSCommunity day. Would love to meet if you’re around.

mrinal's tweet image. At Open Source Summit ⁦@linuxfoundation⁩ #OSSummit this week and today at @OpenSSF’s #SOSSCommunity day.

Would love to meet if you’re around.

Hey everyone! I hope you’re all doing well. Is anyone planning to attend the SOSS Community Day happening in Delhi, India, on 10th December? If you’re going, let me know—I’d love to connect! #SOSSCommunity #thelinuxfoundation #opensource #CONNECT #developer

surajk_umar01's tweet image. Hey everyone!

I hope you’re all doing well.

Is anyone planning to attend the SOSS Community Day happening in Delhi, India, on 10th December?

If you’re going, let me know—I’d love to connect!

#SOSSCommunity #thelinuxfoundation #opensource #CONNECT #developer

OpenSSF、本日開催 #SOSSCommunity 🇯🇵新ゼネラルメンバー Arm、embraceable AI、富士通、新アソシエイトメンバー Ruby Central、Trifecta Techを歓迎 ・新イニシアチブを発表 #OSSセキュリティ を向上させるためのイノベーションを促進 アナウンス参考訳: hubs.la/Q02WfC0-0

Linux_Fdtn_JP's tweet image. OpenSSF、本日開催 #SOSSCommunity 🇯🇵新ゼネラルメンバー Arm、embraceable AI、富士通、新アソシエイトメンバー Ruby Central、Trifecta Techを歓迎
・新イニシアチブを発表 #OSSセキュリティ を向上させるためのイノベーションを促進
アナウンス参考訳:  hubs.la/Q02WfC0-0

#SOSSCommunity セッション風景です!

miraclelinux's tweet image. #SOSSCommunity セッション風景です!
miraclelinux's tweet image. #SOSSCommunity セッション風景です!

#SOSSCommunity 10:20- Future Use of SCAP and SBOM for Software Supply Chain Security 美崎 敦也さん,富田 佑実さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 10:20-
Future Use of SCAP and SBOM for Software Supply Chain Security
美崎 敦也さん,富田 佑実さんが登壇します!


Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀 @SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩 @openssf

infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf

#SOSSCommunity 11:05- Linux Distributor’s Role for Supply Chain Security 鈴木 崇文さん,池田 宗広さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 11:05-
Linux Distributor’s Role for Supply Chain Security
鈴木 崇文さん,池田 宗広さんが登壇します!

#SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! Today, @SanketSudake, @sonali_talks, & @pavan_n_g will be presenting their talks on secure software delivery & AI-driven policy automation✨ See you there📷 @openssf

infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf
infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf

#SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ

miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ
miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ
miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ

#SOSSCommunity 11:05- Linux Distributor’s Role for Supply Chain Security 鈴木 崇文さん,池田 宗広さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 11:05-
Linux Distributor’s Role for Supply Chain Security
鈴木 崇文さん,池田 宗広さんが登壇します!


👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀 #SOSSCommunity

openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity

Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️ Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨ @openssf

infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf

Table Top Exercises at #SOSSCommunity day Japan @openssf where panelists are presented with scenarios and have to come up with responses on stage Interesting format for a panelist discussion

shunghsiyu's tweet image. Table Top Exercises at #SOSSCommunity day Japan @openssf where panelists are presented with scenarios and have to come up with responses on stage

Interesting format for a panelist discussion

🌟 Thank you to the OSS Community for joining us in beautiful Atlanta for #SOSSFusion! Over the past two days, we witnessed the fusion of AI Security, Diversity, and Open Source Public Policy. Next stop: Tokyo, Japan for #SOSSCommunity Day Japan! 🇯🇵

openssf's tweet image. 🌟 Thank you to the OSS Community for joining us in beautiful Atlanta for #SOSSFusion! Over the past two days, we witnessed the fusion of AI Security, Diversity, and Open Source Public Policy. Next stop: Tokyo, Japan for #SOSSCommunity Day Japan! 🇯🇵
openssf's tweet image. 🌟 Thank you to the OSS Community for joining us in beautiful Atlanta for #SOSSFusion! Over the past two days, we witnessed the fusion of AI Security, Diversity, and Open Source Public Policy. Next stop: Tokyo, Japan for #SOSSCommunity Day Japan! 🇯🇵
openssf's tweet image. 🌟 Thank you to the OSS Community for joining us in beautiful Atlanta for #SOSSFusion! Over the past two days, we witnessed the fusion of AI Security, Diversity, and Open Source Public Policy. Next stop: Tokyo, Japan for #SOSSCommunity Day Japan! 🇯🇵
openssf's tweet image. 🌟 Thank you to the OSS Community for joining us in beautiful Atlanta for #SOSSFusion! Over the past two days, we witnessed the fusion of AI Security, Diversity, and Open Source Public Policy. Next stop: Tokyo, Japan for #SOSSCommunity Day Japan! 🇯🇵

🚀 OpenSSF welcomes new members and launches initiatives to advance open source software security! Bringing the community together at #SOSSCOMMUNITY Day Japan during #OSSummit, where leaders and contributors unite to strengthen open source security. hubs.ly/Q02WfR440

openssf's tweet image. 🚀 OpenSSF welcomes new members and launches initiatives to advance open source software security! Bringing the community together at #SOSSCOMMUNITY Day Japan during #OSSummit, where leaders and contributors unite to strengthen open source security.

hubs.ly/Q02WfR440

👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation 📍 #SOSSCommunity Day India

openssf's tweet image. 👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation
📍 #SOSSCommunity Day India
openssf's tweet image. 👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation
📍 #SOSSCommunity Day India

💡 Engage, Learn, Innovate! Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.

openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.
openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.
openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.

Anitha Natarajan & Savita Ashture (Red Hat) discuss securing software supply chains against quantum threats. Learn to migrate to Post Quantum Cryptographic algorithms using Tekton & Sigstore as a reference. 📍 #SOSSCommunity Day India

openssf's tweet image. Anitha Natarajan & Savita Ashture (Red Hat) discuss securing software supply chains against quantum threats. Learn to migrate to Post Quantum Cryptographic algorithms using Tekton & Sigstore as a reference.

📍 #SOSSCommunity Day India

📅 Towards the end of 2024, OpenSSF proudly hosted the inaugural #SOSSCommunity Day India, and we’re excited to share that it was a tremendous success! 🎉Check out the wrap-up blog to relive the highlights and explore the key takeaways. openssf.org/blog/2025/01/0…

openssf's tweet image. 📅 Towards the end of 2024, OpenSSF proudly hosted the inaugural #SOSSCommunity Day India, and we’re excited to share that it was a tremendous success! 🎉Check out the wrap-up blog to relive the highlights and explore the key takeaways. openssf.org/blog/2025/01/0…

It was such a great event by @openssf to bring secure open source community together in India! #SOSSCommunity

👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀 #SOSSCommunity

openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity


👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀 #SOSSCommunity

openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity
openssf's tweet image. 👏 That's a wrap for our first SOSS Community Day in India! 🎉 Thanks to the community for sharing your insights and expertise on #OSSSecurity. As we close out our 2024 events, we’re excited for what’s to come in 2025! 🚀
#SOSSCommunity

Abhimanyu Dhamija from Koalalab talks about securing CI/CD environments, highlighting the complexity of egress-filtering and SSL inspection. Inspired by runtime security, he discusses using BOLT and eBPF for efficient, secure CI pipelines. 📍 #SOSSCommunity Day India

openssf's tweet image. Abhimanyu Dhamija from Koalalab talks about securing CI/CD environments, highlighting the complexity of egress-filtering and SSL inspection. Inspired by runtime security, he discusses using BOLT and eBPF for efficient, secure CI pipelines.

📍 #SOSSCommunity Day India

Sanket Sudake (InfraCloud Technologies) shares how Fission OSS, a serverless platform for Kubernetes, adopted SLSA practices: reproducible builds, signed artifacts, and secure dependency management. 📍 #SOSSCommunity Day India

openssf's tweet image. Sanket Sudake (InfraCloud Technologies) shares how Fission OSS, a serverless platform for Kubernetes, adopted SLSA practices: reproducible builds, signed artifacts, and secure dependency management.

📍 #SOSSCommunity Day India

Anitha Natarajan & Savita Ashture (Red Hat) discuss securing software supply chains against quantum threats. Learn to migrate to Post Quantum Cryptographic algorithms using Tekton & Sigstore as a reference. 📍 #SOSSCommunity Day India

openssf's tweet image. Anitha Natarajan & Savita Ashture (Red Hat) discuss securing software supply chains against quantum threats. Learn to migrate to Post Quantum Cryptographic algorithms using Tekton & Sigstore as a reference.

📍 #SOSSCommunity Day India

Abhinav Sharma (KodeKloud) explores building security-first open source projects using tools like CodeQL, OpenSSF Scorecard, and automated pipelines. Learn to integrate security from day one! 📍 #SOSSCommunity Day India

openssf's tweet image. Abhinav Sharma (KodeKloud) explores building security-first open source projects using tools like CodeQL, OpenSSF Scorecard, and automated pipelines. Learn to integrate security from day one!

📍 #SOSSCommunity Day India

Join Harsh Thakur (@CivoCloud) & Saiyam Pathak (Loft Labs) as they talk about practical steps for achieving #SLSA compliance: ✔️ Generating SBOMs & provenance ✔️ Keyless attestations with cosign ✔️ Hermetic builds with Buildkit 📍 #SOSSCommunity Day India

openssf's tweet image. Join Harsh Thakur (@CivoCloud) & Saiyam Pathak (Loft Labs) as they talk about practical steps for achieving #SLSA compliance:

✔️ Generating SBOMs & provenance
✔️ Keyless attestations with cosign
✔️ Hermetic builds with Buildkit

📍 #SOSSCommunity Day India

👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation 📍 #SOSSCommunity Day India

openssf's tweet image. 👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation
📍 #SOSSCommunity Day India
openssf's tweet image. 👏 Welcome & Opening Remarks by @arungupta, Vice President and General Manager, Developer Programs, Intel Corporation
📍 #SOSSCommunity Day India

💡 Engage, Learn, Innovate! Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.

openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.
openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.
openssf's tweet image. 💡 Engage, Learn, Innovate!
Join us at #SOSSCommunity Day India to explore cutting-edge solutions for open source security. With sessions on education, tooling, and innovation, it’s the place to connect with experts and potential collaborators.

And thanks to @ramiyengar for being the glue that binds the whole openSSF india. #SOSSCommunity

dhamijaabhi's tweet image. And thanks to @ramiyengar for being the glue that binds the whole openSSF india.  #SOSSCommunity

Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️ Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨ @openssf

infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf

Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀 @SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩 @openssf

infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf

#SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! Today, @SanketSudake, @sonali_talks, & @pavan_n_g will be presenting their talks on secure software delivery & AI-driven policy automation✨ See you there📷 @openssf

infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf
infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf

Hey everyone! I hope you’re all doing well. Is anyone planning to attend the SOSS Community Day happening in Delhi, India, on 10th December? If you’re going, let me know—I’d love to connect! #SOSSCommunity #thelinuxfoundation #opensource #CONNECT #developer

surajk_umar01's tweet image. Hey everyone!

I hope you’re all doing well.

Is anyone planning to attend the SOSS Community Day happening in Delhi, India, on 10th December?

If you’re going, let me know—I’d love to connect!

#SOSSCommunity #thelinuxfoundation #opensource #CONNECT #developer

Join me for SOSS Community Day India 2024! cvent.me/G9E8vd?sms=2&c… #SOSSCommunity


Join me for SOSS Community Day India 2024! cvent.me/G9E8vd?sms=2&c… #SOSSCommunity


Join me for SOSS Community Day India 2024! cvent.me/G9E8vd?sms=2&c… #SOSSCommunity


Join me for SOSS Community Day India 2024! cvent.me/G9E8vd?sms=2&c… #SOSSCommunity


Join me for SOSS Community Day India 2024! cvent.me/G9E8vd?sms=2&c… #SOSSCommunity @openssf


No results for "#sosscommunity"

OpenSSF、本日開催 #SOSSCommunity 🇯🇵新ゼネラルメンバー Arm、embraceable AI、富士通、新アソシエイトメンバー Ruby Central、Trifecta Techを歓迎 ・新イニシアチブを発表 #OSSセキュリティ を向上させるためのイノベーションを促進 アナウンス参考訳: hubs.la/Q02WfC0-0

Linux_Fdtn_JP's tweet image. OpenSSF、本日開催 #SOSSCommunity 🇯🇵新ゼネラルメンバー Arm、embraceable AI、富士通、新アソシエイトメンバー Ruby Central、Trifecta Techを歓迎
・新イニシアチブを発表 #OSSセキュリティ を向上させるためのイノベーションを促進
アナウンス参考訳:  hubs.la/Q02WfC0-0

#SOSSCommunity セッション風景です!

miraclelinux's tweet image. #SOSSCommunity セッション風景です!
miraclelinux's tweet image. #SOSSCommunity セッション風景です!

#SOSSCommunity 10:20- Future Use of SCAP and SBOM for Software Supply Chain Security 美崎 敦也さん,富田 佑実さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 10:20-
Future Use of SCAP and SBOM for Software Supply Chain Security
美崎 敦也さん,富田 佑実さんが登壇します!


How prevalent is #OpenSource? It’s *everywhere*. Here are impressive stats. Yay! We won! 🥳🎆🎇 But what does that mean…? 🤔 #SOSSCommunity

webchick's tweet image. How prevalent is #OpenSource? It’s *everywhere*. Here are impressive stats.

Yay! We won! 🥳🎆🎇

But what does that mean…? 🤔 #SOSSCommunity

#SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ

miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ
miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ
miraclelinux's tweet image. #SOSSCommunity セッション風景です!☆ζ(。☌ᴗ☌。)ζ

#SOSSCommunity 11:05- Linux Distributor’s Role for Supply Chain Security 鈴木 崇文さん,池田 宗広さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 11:05-
Linux Distributor’s Role for Supply Chain Security
鈴木 崇文さん,池田 宗広さんが登壇します!


Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️ Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨ @openssf

infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf
infracloudio's tweet image. Finalizing the right policies to secure #K8s clusters takes a lot of manual effort🛠️

Watch @sonali_talks & @pavan_n_g at #SOSSCommunity Day to learn how to use AI tools like #clio, #k8sGPT & #GPTScript to automate policy checks to suggest optimal policies✨

@openssf

#SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! Today, @SanketSudake, @sonali_talks, & @pavan_n_g will be presenting their talks on secure software delivery & AI-driven policy automation✨ See you there📷 @openssf

infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf
infracloudio's tweet image. #SOSSCOMMUNITY Day is the perfect prologue to #KubeCon India for InfraCloud team! 

Today, @SanketSudake, @sonali_talks, & @pavan_n_g
will be presenting their talks on secure software delivery & AI-driven policy automation✨

See you there📷

@openssf

Ok here’s where we are at. How do we make sure that the newly updated system is secure and not used as a secondary attack vector? #SOSSCommunity

webchick's tweet image. Ok here’s where we are at. How do we make sure that the newly updated system is secure and not used as a secondary attack vector?

#SOSSCommunity

Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀 @SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩 @openssf

infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf
infracloudio's tweet image. Building a secure software supply chain is essential for quality delivery, but there are many soft spots to watch out for👀

@SanketSudake at #SOSSCommunity Day, sharing how he adopted secure software delivery practices for @fissionio & the challenges he faced🧩

@openssf

There are many points along the way from initial development through to deployment where vulnerabilities could be introduced. #SOSSCommunity

webchick's tweet image. There are many points along the way from initial development through to deployment where vulnerabilities could be introduced.

#SOSSCommunity

But it’s not just about software stuff, there are also *people* 😱 — both maintainers *and* end users — downstream impacts will also impact how much people are willing to update to more secure code. #SOSSCommunity

webchick's tweet image. But it’s not just about software stuff, there are also *people* 😱 — both maintainers *and* end users — downstream impacts will also impact how much people are willing to update to more secure code. #SOSSCommunity
webchick's tweet image. But it’s not just about software stuff, there are also *people* 😱 — both maintainers *and* end users — downstream impacts will also impact how much people are willing to update to more secure code. #SOSSCommunity

Well first off, there are So. Many. Packages. 😭 #SOSSCommunity

webchick's tweet image. Well first off, there are So. Many. Packages. 😭 #SOSSCommunity
webchick's tweet image. Well first off, there are So. Many. Packages. 😭 #SOSSCommunity

A framework for evaluating #OpenSource projects: 1. Is it active? 2. Is there governance? 3. Do releases come on a cadence? 4. Is community engaged? 5. What’s the bug reporting projects? A WELL CARED FOR PROJECT IS A MORE SECURE PROJECT. #SOSSCommunity

webchick's tweet image. A framework for evaluating #OpenSource projects:

1. Is it active?
2. Is there governance?
3. Do releases come on a cadence?
4. Is community engaged?
5. What’s the bug reporting projects?

A WELL CARED FOR PROJECT IS A MORE SECURE PROJECT.

#SOSSCommunity

Every time a high-profile incident happens in #OpenSource, it shakes confidence. How do we respond? @OpenSSF tries to solve this issue, but we all need to engage. *Take responsibility for software you’re using.* “The community” won’t fix it. (Free as in puppy.) #SOSSCommunity

webchick's tweet image. Every time a high-profile incident happens in #OpenSource, it shakes confidence. How do we respond?

@OpenSSF tries to solve this issue, but we all need to engage.

*Take responsibility for software you’re using.* “The community” won’t fix it. (Free as in puppy.)

#SOSSCommunity

Ensure repo is as secure as possible. Pull back who has access to repo, introduce review process, ensure CI/CD tests passing *before* pushing code. CI/CD: could the security issue be embedded here? Can you pin to specific container image? Signed commits? #SOSSCommunity

webchick's tweet image. Ensure repo is as secure as possible. Pull back who has access to repo, introduce review process, ensure CI/CD tests passing *before* pushing code.

CI/CD: could the security issue be embedded here? Can you pin to specific container image? Signed commits?

#SOSSCommunity

Here’s an example (predates #xzbackdoor). Once the vulnerability is fixed, you need to get the word out, *fast*. #SOSSCommunity CPEs are a tool, but #PyPi has 500K projects (!) and this doesn’t scale, esp with volunteer maintainers.

webchick's tweet image. Here’s an example (predates #xzbackdoor). Once the vulnerability is fixed, you need to get the word out, *fast*. #SOSSCommunity

CPEs are a tool, but #PyPi has 500K projects (!) and this doesn’t scale, esp with volunteer maintainers.
webchick's tweet image. Here’s an example (predates #xzbackdoor). Once the vulnerability is fixed, you need to get the word out, *fast*. #SOSSCommunity

CPEs are a tool, but #PyPi has 500K projects (!) and this doesn’t scale, esp with volunteer maintainers.
webchick's tweet image. Here’s an example (predates #xzbackdoor). Once the vulnerability is fixed, you need to get the word out, *fast*. #SOSSCommunity

CPEs are a tool, but #PyPi has 500K projects (!) and this doesn’t scale, esp with volunteer maintainers.

OSV database — aims to be precise about versions affected, recommendations about whether you’re vulnerable, and allow for automations. For example, log4j is 6 levels deep, and all 6 levels need to be patched. Versus something surface level Prioritize by impact. #SOSSCommunity

webchick's tweet image. OSV database — aims to be precise about versions affected, recommendations about whether you’re vulnerable, and allow for automations.

For example, log4j is 6 levels deep, and all 6 levels need to be patched. Versus something surface level

Prioritize by impact.

#SOSSCommunity

発表案募集 #SOSSCommunity Day 🇯🇵 (10/30 東京) #セキュリティ#OSS エコシステム全体のコミュニティメンバーが集まり、私たち全員が依存しているOSSの開発・保守・使用を持続的にセキュアにする能力や機能に関するアイデアや進捗を共有するイベントです CFP8/25 まで: hubs.la/Q02JQFgP0

Linux_Fdtn_JP's tweet image. 発表案募集 #SOSSCommunity Day 🇯🇵 (10/30 東京)

#セキュリティ と #OSS エコシステム全体のコミュニティメンバーが集まり、私たち全員が依存しているOSSの開発・保守・使用を持続的にセキュアにする能力や機能に関するアイデアや進捗を共有するイベントです
 
CFP8/25 まで: hubs.la/Q02JQFgP0

#SOSSCommunity 11:05- Linux Distributor’s Role for Supply Chain Security 鈴木 崇文さん,池田 宗広さんが登壇します!

miraclelinux's tweet image. #SOSSCommunity 11:05-
Linux Distributor’s Role for Supply Chain Security
鈴木 崇文さん,池田 宗広さんが登壇します!

And thanks to @ramiyengar for being the glue that binds the whole openSSF india. #SOSSCommunity

dhamijaabhi's tweet image. And thanks to @ramiyengar for being the glue that binds the whole openSSF india.  #SOSSCommunity

Next up: @KatherineD and Ryan Ware (sorry, couldn’t find you!) talk consuming #OpenSource securely! #SOSSCommunity

webchick's tweet image. Next up: @KatherineD and Ryan Ware (sorry, couldn’t find you!) talk consuming #OpenSource securely!

#SOSSCommunity

Loading...

Something went wrong.


Something went wrong.


United States Trends