The New Stack Podcast cover image

The Risks of Decomposing Software Components

The New Stack Podcast

00:00

How to Verify the Veracity of Open Source Components

Security is about predictable, reproducible builds. There's a high degree of variability in quality across the open source landscape. We have a project that the OpenSSF called the Security Scorecard which runs automatically across one million different repositories at GitHub. This is how we go and prevent the next log for shell vulnerability being a major disaster. I'll just end with this. The log for J developers, their professionals, they were working diligently against a set of features that they wanted. They were fixing bugs. Yeah. You know, they were triaging reports, but there's this section of code that didn't quite have the attention. Everything else did that it turned out there had been this bug

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app