|
[AR] Please review WG Charter and vote on Issue 103 to adopt or not
Team – please review Issue 103(1) and review our WG Charter and express your vote so we can close this matter. Thanks all! - https://github.com/ossf/wg-best-practices-os-developers/issues/103 Cheers,
Team – please review Issue 103(1) and review our WG Charter and express your vote so we can close this matter. Thanks all! - https://github.com/ossf/wg-best-practices-os-developers/issues/103 Cheers,
|
By
CRob Robinson (Intel)
·
|
|
FYI: GitHub now supports private vulnerability reporting!!!
All, FYI: GitHub now supports private reporting of security vulnerabilities to projects! This is a big deal. Details here: https://docs.github.com/en/code-security/security-advisories/guidance-on-repo
All, FYI: GitHub now supports private reporting of security vulnerabilities to projects! This is a big deal. Details here: https://docs.github.com/en/code-security/security-advisories/guidance-on-repo
|
By
David A. Wheeler
·
|
|
[OpenSSF] The US Securing Open Source Software Act of 2022 is a step in the right direction
Subject: [OpenSSF] The US Securing Open Source Software Act of 2022 is a step in the right direction Good day from Singapore, I have just come across this article. Sharing it for more awareness. Artic
Subject: [OpenSSF] The US Securing Open Source Software Act of 2022 is a step in the right direction Good day from Singapore, I have just come across this article. Sharing it for more awareness. Artic
|
By
Turritopsis Dohrnii Teo En Ming
·
|
|
Security fundamentals course - strong objections to Ashley Madison story time?
I propose adding to the fundamentals security course an example using Ashley Madison. You can see the proposed text here: https://github.com/ossf/secure-sw-dev-fundamentals/pull/105 The full story is
I propose adding to the fundamentals security course an example using Ashley Madison. You can see the proposed text here: https://github.com/ossf/secure-sw-dev-fundamentals/pull/105 The full story is
|
By
David A. Wheeler
·
|
|
Suggestions for other story times?
All: Feedback on the "Secure Software Development Fundamentals course" indicated that many really liked our "Story Time" sections. These give specific real-world examples of attacks. As a result, I pl
All: Feedback on the "Secure Software Development Fundamentals course" indicated that many really liked our "Story Time" sections. These give specific real-world examples of attacks. As a result, I pl
|
By
David A. Wheeler
·
|
|
Scorecards prominently noted in Sonatype's 2022 report
In case you didn't see it, there's lots of info in Sonatype's 8th annual "State of the Software Supply Chain Report" (2022): https://www.sonatype.com/state-of-the-software-supply-chain/introduction It
In case you didn't see it, there's lots of info in Sonatype's 8th annual "State of the Software Supply Chain Report" (2022): https://www.sonatype.com/state-of-the-software-supply-chain/introduction It
|
By
David A. Wheeler
·
|
|
Housekeeping FYIs - Holiday Calendars and Slack Apps
Hi all, As discussed on the TAC call yesterday, just a quick note to share that: We will be cancelling all OpenSSF meetings during the holiday periods of Nov. 24-25 and Dec. 26-30. Please let us know
Hi all, As discussed on the TAC call yesterday, just a quick note to share that: We will be cancelling all OpenSSF meetings during the holiday periods of Nov. 24-25 and Dec. 26-30. Please let us know
|
By
Jory Burson (PM, LF)
·
|
|
OpenSSF Office Hours session 1 announcement: final review
Dear all, I'm happy to announce that we're approaching the first session of the Office Hours. Below is the announcement message (based on the work of Michael S), please review in the next hours. The c
Dear all, I'm happy to announce that we're approaching the first session of the Office Hours. Below is the announcement message (based on the work of Michael S), please review in the next hours. The c
|
By
Marta Rybczynska
·
|
|
Proposed short section on AI/ML security for the fundamentals course
All: I created a proposed short section on securing AI/ML for the fundamentals course: https://github.com/ossf/secure-sw-dev-fundamentals/pull/91 I wish there were better/more complete answers, but be
All: I created a proposed short section on securing AI/ML for the fundamentals course: https://github.com/ossf/secure-sw-dev-fundamentals/pull/91 I wish there were better/more complete answers, but be
|
By
David A. Wheeler
·
|
|
OpenSSF office hours: new dates proposed
Hello all, OpenSSF Office Hours is an initiative to organize regular calls where open source maintainers can come and ask their security-related questions. For that to work we need security experts. T
Hello all, OpenSSF Office Hours is an initiative to organize regular calls where open source maintainers can come and ask their security-related questions. For that to work we need security experts. T
|
By
Marta Rybczynska
·
|
|
[Help Requested] UX for Scorecard API
Hi folks, Scorecard badges launched a few weeks ago and developers have already started interacting with it (yay!). A common feedback we received is - clicking through the badge returns a JSON blob an
Hi folks, Scorecard badges launched a few weeks ago and developers have already started interacting with it (yay!). A common feedback we received is - clicking through the badge returns a JSON blob an
|
By
azeems@...
·
|
|
FYI: concise guides & npm guide are visible from openssf.org website
All: I wasn't sure id this was already clear, so I'm posting. The main OpenSSF site (openssf.org), under Resources -> Guides, links to this page with a list of guides: https://openssf.org/resources/gu
All: I wasn't sure id this was already clear, so I'm posting. The main OpenSSF site (openssf.org), under Resources -> Guides, links to this page with a list of guides: https://openssf.org/resources/gu
|
By
David A. Wheeler
·
|
|
[Action Requested] Steps to be credited as a WG Member in LFX Platform
Hello! OpenSSF Staff are undertaking an effort to provide better data and reporting to our community in a number of different ways. One of these ways is to gauge Working Group and committee participat
Hello! OpenSSF Staff are undertaking an effort to provide better data and reporting to our community in a number of different ways. One of these ways is to gauge Working Group and committee participat
|
By
Jory Burson (PM, LF)
·
|
|
[FYI] No WG Call 13September - enjoy OSS-EU's OpenSSF Day! /eom
$SUBJECT Cheers, CRob Director of Security Communications Intel Product Assurance and Security
$SUBJECT Cheers, CRob Director of Security Communications Intel Product Assurance and Security
|
By
CRob Robinson (Intel)
·
|
|
Concise guides appear to be completed - if there's an important issue, please raise it ASAP
2 messages
All: I believe we've completed the first versions of our two "concise guides": 1. Concise Guide for Developing More Secure Software https://github.com/ossf/wg-best-practices-os-developers/blob/main/do
All: I believe we've completed the first versions of our two "concise guides": 1. Concise Guide for Developing More Secure Software https://github.com/ossf/wg-best-practices-os-developers/blob/main/do
|
By
David A. Wheeler
·
|
|
Best Practices badge now has >5,000 participating projects
FYI: The Best Practices Badge project now has over 5,000 participating projects. This makes sense because we've had continuous growth. As of 2022-07-30 there were 4,930; as of 2022-08-30 there were 5,
FYI: The Best Practices Badge project now has over 5,000 participating projects. This makes sense because we've had continuous growth. As of 2022-07-30 there were 4,930; as of 2022-08-30 there were 5,
|
By
David A. Wheeler
·
|
|
Updating vulnerable dependencies is possible (best practices badge project & omniauth)
2 messages
FYI: Here's another story showing it's possible to plan for & rapidly handle vulnerable dependencies, as outlined in "Concise Guide for Developing More Secure Software". --- David A. Wheeler =========
FYI: Here's another story showing it's possible to plan for & rapidly handle vulnerable dependencies, as outlined in "Concise Guide for Developing More Secure Software". --- David A. Wheeler =========
|
By
David A. Wheeler
·
|
|
[FYI] No Working Group call 13 Sept (OSS-EU Conference & OpenSSF Day)
Team – we will not be meeting on 13September. Many of us will be in Dublin at the OSS-EU conference and participating in OpenSSF day. We will be formally announcing our Concise Guides as part of the c
Team – we will not be meeting on 13September. Many of us will be in Dublin at the OSS-EU conference and participating in OpenSSF day. We will be formally announcing our Concise Guides as part of the c
|
By
CRob Robinson (Intel)
·
|
|
Concise guides - final drafts ready!
3 messages
All: We now have two new final-draft documents produced by the OpenSSF Best Practices Working Group. I propose that we vote for their approval at our next meeting. Details & links below. --- David A.
All: We now have two new final-draft documents produced by the OpenSSF Best Practices Working Group. I propose that we vote for their approval at our next meeting. Details & links below. --- David A.
|
By
David A. Wheeler
·
|
|
FYI: Fundamentals course statistics
FYI, here are some statistics for the secure software development fundamentals courses, as of today. --- David A. Wheeler ====================== LFD 121 is on the Linux Foundation T&C platform, and th
FYI, here are some statistics for the secure software development fundamentals courses, as of today. --- David A. Wheeler ====================== LFD 121 is on the Linux Foundation T&C platform, and th
|
By
David A. Wheeler
·
|