
The Risks of Decomposing Software Components
The New Stack Podcast
00:00
How to Verify the Veracity of Open Source Components
Security is about predictable, reproducible builds. There's a high degree of variability in quality across the open source landscape. We have a project that the OpenSSF called the Security Scorecard which runs automatically across one million different repositories at GitHub. This is how we go and prevent the next log for shell vulnerability being a major disaster. I'll just end with this. The log for J developers, their professionals, they were working diligently against a set of features that they wanted. They were fixing bugs. Yeah. You know, they were triaging reports, but there's this section of code that didn't quite have the attention. Everything else did that it turned out there had been this bug
Transcript
Play full episode