|
[RFC] OSSF WH OS Summit II proposal - Developer Best Practices
Hey team – I was fortunate to be involved in the recent Summit in DC around improving OSS security. Unsurprisingly, there are some items in the plan that are heavily related to our work. I’d love to t
Hey team – I was fortunate to be involved in the recent Summit in DC around improving OSS security. Unsurprisingly, there are some items in the plan that are heavily related to our work. I’d love to t
|
By
CRob Robinson (Intel)
·
|
|
I can use generated images from Dall-E / Dall-E-2 to illustrate the developing secure software course!
3 messages
All, FYI: Dall-E-2 uses machine learning techniques to generate imagery from text. See: https://openai.com/dall-e-2/ I've received confirmation from OpenAI that once we get access to Dall-E-2, we can
All, FYI: Dall-E-2 uses machine learning techniques to generate imagery from text. See: https://openai.com/dall-e-2/ I've received confirmation from OpenAI that once we get access to Dall-E-2, we can
|
By
David A. Wheeler
·
|
|
Fundamentals course tweaked on parameterized statements vs. prepared statements - comments welcome!
All: I've created a proposed change for the "fundamentals" course on SQL injection, primarily to distinguish "parameterized statements" from "prepared statements". In many APIs "prepared statements" &
All: I've created a proposed change for the "fundamentals" course on SQL injection, primarily to distinguish "parameterized statements" from "prepared statements". In many APIs "prepared statements" &
|
By
David A. Wheeler
·
|
|
Scorecard/Allstar Mission/Vision working session (5/5)
2 messages
Scorecard and Allstar project enthusiasts! Our next biweekly combined project meeting (5/5) will be a working session to discuss and craft mission statements and visions for both projects. Ahead of th
Scorecard and Allstar project enthusiasts! Our next biweekly combined project meeting (5/5) will be a working session to discuss and craft mission statements and visions for both projects. Ahead of th
|
By
Stephen Augustus (augustus)
·
|
|
FYI, Best Practices badge updated for vulnerable components
2 messages
FYI: The best practices badge project just did some routine updates of some of our dependencies because vulnerabilities in them were publicly announced yesterday. I thought I should provide some detai
FYI: The best practices badge project just did some routine updates of some of our dependencies because vulnerabilities in them were publicly announced yesterday. I thought I should provide some detai
|
By
David A. Wheeler
·
|
|
Updating fundamentals course for 2021 OWASP Top 10 and 2021 CWE Top 25
The GitHub markdown version of the "Fundamentals" course has been recently updated to reference every major point in the 2021 OWASP Top 10 & the 2021 CWE Top 25. See: https://github.com/ossf/secure-sw
The GitHub markdown version of the "Fundamentals" course has been recently updated to reference every major point in the 2021 OWASP Top 10 & the 2021 CWE Top 25. See: https://github.com/ossf/secure-sw
|
By
David A. Wheeler
·
|
|
One-page summary: Should we tend to have *separate* numbered points, or tend to *combine* items into 1 numbered point? (Greco-Roman Wrestling)
3 messages
All: At the last OpenSSF Best Practices WG meeting, there was an agreement with my proposal to add a project/task to create a "one-page" guide for software developers, along with a supporting one-page
All: At the last OpenSSF Best Practices WG meeting, there was an agreement with my proposal to add a project/task to create a "one-page" guide for software developers, along with a supporting one-page
|
By
David A. Wheeler
·
|
|
Trouble with Zoom Login today
Having a boggle with the OSSF Zoom account, trying to get logged in. Hopefully we’ll start soon. Cheers, CRob Director of Security Communications Intel Product Assurance and Security
Having a boggle with the OSSF Zoom account, trying to get logged in. Hopefully we’ll start soon. Cheers, CRob Director of Security Communications Intel Product Assurance and Security
|
By
CRob Robinson (Intel)
·
|
|
Proposal: One-page "how to develop secure software" guide (including build/distribution integrity)
2 messages
The OpenSSF & others have developed many things, but I've been repeatedly asked for a *short* guidance document (around a page) that tells people "what to do" & links to the details. I propose that th
The OpenSSF & others have developed many things, but I've been repeatedly asked for a *short* guidance document (around a page) that tells people "what to do" & links to the details. I propose that th
|
By
David A. Wheeler
·
|
|
"Secure Software Development" course now available on LF Training Portal
All: Today the OpenSSF and LF Training & Certification announced the immediate availability of a free online training course, "Developing Secure Software". The course content mirrors the Secure Softwa
All: Today the OpenSSF and LF Training & Certification announced the immediate availability of a free online training course, "Developing Secure Software". The course content mirrors the Secure Softwa
|
By
David A. Wheeler
·
|
|
Infinity diagram
I really like the flashy *look* of the "infinity" diagram at wg-best-practices-os-developers/infinity2/index.html It's cool!! However, I don't like most of its current *categories*. I think they shoul
I really like the flashy *look* of the "infinity" diagram at wg-best-practices-os-developers/infinity2/index.html It's cool!! However, I don't like most of its current *categories*. I think they shoul
|
By
David A. Wheeler
·
|
|
Plan to add a new platform for the "Secure Software Development Fundamentals" course(s) beyond edX, with no-cost certificate test
All, FYI: There are new plans in the works to add a new platform for the "Secure Software Development Fundamentals" courses, specifically the Linux Foundation Training & Certification platform. This w
All, FYI: There are new plans in the works to add a new platform for the "Secure Software Development Fundamentals" courses, specifically the Linux Foundation Training & Certification platform. This w
|
By
David A. Wheeler
·
|
|
Announcement: Linux Security Summit North America 2022
The Linux Security Summit (LSS) is coming up, and some here may wish to present and/or attend. See below for details. The Call for Proposals (CFP) closes March 30. --- David A. Wheeler ===============
The Linux Security Summit (LSS) is coming up, and some here may wish to present and/or attend. See below for details. The Call for Proposals (CFP) closes March 30. --- David A. Wheeler ===============
|
By
David A. Wheeler
·
|
|
[FYI] Upcoming call on OSS Security Maturity Models 2March2022
Hi teams – Just as a reminder, Wednesday at 10am EST we’ll be meeting with several folks from sig.eu to discuss open source software security models. If you are interested, please join us a the link b
Hi teams – Just as a reminder, Wednesday at 10am EST we’ll be meeting with several folks from sig.eu to discuss open source software security models. If you are interested, please join us a the link b
|
By
CRob Robinson (Intel)
·
|
|
Reducing Security Risks in Open Source Software at Scale: Scorecards Launches V4
Hi All, We're thrilled to announce the Scorecards V4 release! This includes 1M repos scanned weekly and a new Dangerous-Workflow check. We’re particularly excited about the new GitHub Action that inte
Hi All, We're thrilled to announce the Scorecards V4 release! This includes 1M repos scanned weekly and a new Dangerous-Workflow check. We’re particularly excited about the new GitHub Action that inte
|
By
Jennifer Bonner (Linux Foundation)
·
|
|
Are there any tokens still available?
Hi, Some projects were slow to react to the offer and are only responding now. Do we still have some tokens to distribute? My understanding is that the coupon for the Titan tokens has expired but what
Hi, Some projects were slow to react to the offer and are only responding now. Do we still have some tokens to distribute? My understanding is that the coupon for the Titan tokens has expired but what
|
By
Arnaud Le Hors
·
|
|
Offer MFA tokens to log4j developers?
4 messages
It's clear we have some leftover MFA tokens. I'd like to offer MFA tokens to all 10 of the log4j developers; log4j has been added the critical projects WG's list of critical projects. https://logging.
It's clear we have some leftover MFA tokens. I'd like to offer MFA tokens to all 10 of the log4j developers; log4j has been added the critical projects WG's list of critical projects. https://logging.
|
By
David A. Wheeler
·
|
|
MFA codes sent!!
2 messages
All: Good news! The Google & GitHub codes have been sent to projects who told us they wanted some & how many of each they wanted. I plan to post some stats, but currently we're too busy trying to dist
All: Good news! The Google & GitHub codes have been sent to projects who told us they wanted some & how many of each they wanted. I plan to post some stats, but currently we're too busy trying to dist
|
By
David A. Wheeler
·
|
|
Send the MFA token codes!
The deadlines have passed - let's start distributing MFA tokens!! Appu: Please start sending via email the Google coupon codes to the OSS projects that have requested one or more Titan tokens in our s
The deadlines have passed - let's start distributing MFA tokens!! Appu: Please start sending via email the Google coupon codes to the OSS projects that have requested one or more Titan tokens in our s
|
By
David A. Wheeler
·
|
|
[+1's Requested] Scorecards Automation Improvements project
Best Practices Squad, The Scorecards team have scoped work and identified a well-qualified contractor to execute on scorecards automation improvements/fixes as well as some minor work on Allstar. The
Best Practices Squad, The Scorecards team have scoped work and identified a well-qualified contractor to execute on scorecards automation improvements/fixes as well as some minor work on Allstar. The
|
By
Jory Burson (PM, LF)
·
|