AI EXPRESS
  • AI
    A close up of a microphone.

    IRS expands voice bot options for faster service

    HCL Technologies DRYiCE launches full-stack AIOps and observability solution

    HCL Technologies DRYiCE launches full-stack AIOps and observability solution

    Google places engineer on leave after claim LaMDA is ‘sentient’

    Google places engineer on leave after claim LaMDA is ‘sentient’

    Google employs ML to make Chrome more secure and enjoyable

    Google employs ML to make Chrome more secure and enjoyable

    Axon’s AI ethics board resign after TASER drone announcement

    Axon’s AI ethics board resign after TASER drone announcement

    IBM’s AI-powered Mayflower ship crosses the Atlantic

    IBM’s AI-powered Mayflower ship crosses the Atlantic

  • ML
    Remove Item From List Python

    How to Remove an Item From List Python

    Choose specific timeseries to forecast with Amazon Forecast

    Choose specific timeseries to forecast with Amazon Forecast

    python main

    Python Main Function and Examples with Code

    Import data from cross-account Amazon Redshift in Amazon SageMaker Data Wrangler for exploratory data analysis and data preparation

    Import data from cross-account Amazon Redshift in Amazon SageMaker Data Wrangler for exploratory data analysis and data preparation

    Fully Automating Server-side Object Detection Workflows – The Official Blog of BigML.com

    Fully Automating Server-side Object Detection Workflows –

    A Guide to installing Python Pip in 2022

    A Guide to installing Python Pip in 2022

    Accelerate your career with ML skills through the AWS Machine Learning Engineer Scholarship

    Accelerate your career with ML skills through the AWS Machine Learning Engineer Scholarship

    Programmable Object Detection, Fast and Easy – The Official Blog of BigML.com

    Programmable Object Detection, Fast and Easy –

    python substring

    Python Substring: What is a String in Python?

  • NLP
    AI Favors Autocracy, But Democracies Can Still Fight Back

    AI Favors Autocracy, But Democracies Can Still Fight Back

    25 projects highlighted at COMPSPEX event

    25 projects highlighted at COMPSPEX event

    Global Cloud Natural Language Processing Market

    Cloud Natural Language Processing Market to Eyewitness Massive Growth by 2031 – Designer Women

    Artificial Intelligence in the 4th Industrial Revolution

    Artificial Intelligence in the 4th Industrial Revolution

    SAS honors teams from around globe in global Hackathon event

    SAS honors teams from around globe in global Hackathon event

    Assistant / Associate Professor, College of Information Technology job with UNITED ARAB EMIRATES UNIVERSITY

    Assistant / Associate Professor, College of Information Technology job with UNITED ARAB EMIRATES UNIVERSITY

    OctoML CEO: MLOps needs to step aside for DevOps

    OctoML CEO: MLOps needs to step aside for DevOps

    ‘Europe has fallen behind in AI commercialisation’

    ‘Europe has fallen behind in AI commercialisation’

    CyberSaint Releases CyberStrong Version 3.20 Empowering Customers to Further Automate the Cyber & IT Risk Management Function

    CyberSaint Releases CyberStrong Version 3.20 Empowering Customers to Further Automate the Cyber & IT Risk Management Function

  • Vision
    Writing ResNet from Scratch in PyTorch

    Writing ResNet from Scratch in PyTorch

    Introduction to Pattern Matching

    Introduction to Pattern Matching

    viso.ai Logo

    MediaPipe: Google’s Open Source Framework for ML solutions (2022 Guide)

    Image Classification with Attention

    Image Classification with Attention

    viso.ai Logo

    Deep Reinforcement Learning: How It Works and Real World Examples

    viso.ai Logo

    Deep Face Recognition: An Easy-To-Understand Overview

    viso.ai Logo

    Image Data Augmentation for Computer Vision in 2022 (Guide)

    What’s Trending in Machine Vision? Part 4

    What’s Trending in Machine Vision? Part 4

    viso.ai Logo

    Object Detection in 2022: The Definitive Guide

  • Robotics
    cruise robotaxis in San Francisco

    Cruise hits milestone by charging for robotaxis rides

    UR20 cobot Universal Robots

    Anders Beck introduces the UR20; California bans autonomous tractors

    Are farmers ready for autonomous tractors?

    Calif.’s ongoing ban of autonomous tractors a major setback

    robots in mine

    Hiring levels for robotics jobs in mining hit year high in May

    Synkar offers sidewalk delivery as a service

    Synkar offers sidewalk delivery as a service

    Robust.AI announces new Grace software suite

    Robust.AI announces new Grace software suite

    osaro robot picks items for customer order

    OSARO automates Zenni fulfillment center

    csail simulation

    MIT CSAIL releases open-source simulator for autonomous vehicles

    proteus robot

    A decade after acquiring Kiva, Amazon unveils its first AMR

  • RPA
    Take employee experience into hyperdrive with Hyperautomation

    Hyperautomation- Your Answer to Enhance Employee Experience| AutomationEdge

    Know Why Automation Now Resides in the Heart of Customer Contact Centers| AutomationEdge

    Know Why Automation Now Resides in the Heart of Customer Contact Centers| AutomationEdge

    Conversational AI, Healing the Healthcare Industry| AutomationEdge

    Conversational AI, Healing the Healthcare Industry| AutomationEdge

    Reimagining the Ideal Service Desk with Conversational IT and AI

    Reimagining the Ideal Service Desk with Conversational IT and AI

    Breaking Through All the Customer Engagement Myths with Conversational AI

    Breaking Through All the Customer Engagement Myths with Conversational AI

    Reimagine and Recreate Customer Engagement with Conversational AI

    Reimagine and Recreate Customer Engagement with Conversational AI

    Invoice Management Made Easy With Automation and RPA solution

    Automated Invoice Processing: An Ardent Need of Modern Day Businesses

    Conversational AI- Oomphing Up HR Digitization Factor| AutomationEdge

    Conversational AI- Oomphing Up HR Digitization Factor| AutomationEdge

    Know how to Implement Conversational AI

    Alarm Ringing! Top 10 Tips to go about Conversational Marketing

  • Gaming
    EA to reveal Skate 4 in July - report

    EA to reveal Skate 4 in July – report

    Bungie suing person responsible for multiple fraudulent Destiny 2 DMCA takedowns

    Bungie suing person responsible for multiple fraudulent Destiny 2 DMCA takedowns

    Best Sonic Games Of All Time

    Best Sonic Games Of All Time

    Rumor has it Skull and Bones will be re-revealed in early July

    Rumor has it Skull and Bones will be re-revealed in early July

    Persona 5 fan zine founder syphons roughly $21,000 of raised funds - allegedly into Genshin Impact

    Persona 5 fan zine founder syphons roughly $21,000 of raised funds – allegedly into Genshin Impact

    Confusion reigns over PS Plus Premium's Classics catalogue

    Confusion reigns over PS Plus Premium’s Classics catalogue

    Stardew Valley Creator Working On Version 1.6, Includes "Some New Content"

    Stardew Valley Creator Working On Version 1.6, Includes “Some New Content”

    Why wait for another Fire Emblem when you can play Shining Force instead?

    Why wait for another Fire Emblem when you can play Shining Force instead?

    FromSoftware's next game in final stages of development as studio looks to beef up staff for multiple projects

    FromSoftware’s next game in final stages of development as studio looks to beef up staff for multiple projects

  • Investment
    Tibit Raises $30M in Series C Funding

    Tibit Raises $30M in Series C Funding

    Mana Interactive Raises Over $7M IN Seed Funding

    System 9 Closes $5.7M Series A Funding Round

    Prime Trust Raises Over $100M in Series B Funding

    Prime Trust Raises Over $100M in Series B Funding

    Post Script Media

    Post Script Media Raises $2M in Funding

    Evinced_Logo

    Evinced Raises $38M in Series B Funding

    CityFALCON Logo

    CityFALCON Raises $2M in Finding

    HourWork Raises $10M in Series A Funding

    Unify Jobs Raises $4.5M in Seed Funding

    Codetta Biosciences Raises $15M in Series A Financing

    Mojia Biotech Completes $80M Series B Financing

    ConductorOne

    ConductorOne Raises $15M in Series A Funding

  • More
    • Data analytics
    • Apps
    • No Code
    • Cloud
    • Quantum Computing
    • Security
    • AR & VR
    • Esports
    • IOT
    • Smart Home
    • Smart City
    • Crypto Currency
    • Blockchain
    • Reviews
    • Video
No Result
View All Result
AI EXPRESS
No Result
View All Result
Home Security

OpenSSF details advancements in open-source security efforts

by
June 21, 2022
in Security
0
OpenSSF details advancements in open-source security efforts
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

We’re excited to deliver Remodel 2022 again in-person July 19 and just about July 20 – 28. Be a part of AI and knowledge leaders for insightful talks and thrilling networking alternatives. Register at present!


Open-source safety is at the moment present process a interval of accelerated change, thanks in no small half to the efforts of the Linux Basis’s OpenSSF (Open Supply Safety Basis).

In a full-day occasion on the Open Supply Summit on June 20, supporters, leaders and contributors to OpenSSF mentioned the present state of open-source safety and detailed, at nice size, a number of efforts underway to assist enhance the present state of affairs. The OpenSSF has been busy in 2022 because it has ramped up a mobilization effort that it expects will value $150 million to assist safe open-source software program. The mobilization effort is just one within the bigger set of initiatives that the OpenSSF has underway.

“We’re form of a circus, I say that lovingly and a few of you want going to the circus,” Brian Behlendorf, OpenSSF normal supervisor stated in a session on the Open Supply Summit occasion. “There are many issues happening at OpenSSF, a number of totally different groups and that is part of our power.”

The a number of rings of the OpenSSF open-source safety circus tent

Behlendorf recognized three key rings as main objectives for the OpenSSF: Securing the manufacturing of open-source software program, bettering vulnerability discovery and remediation, and shortening the time it takes to patch and reply to points.

These objectives are executed throughout efforts led by a number of working teams on the OpenSSF. The working teams at the moment lively embody est practices, vulnerability disclosure, safety tooling, safety risk identification, provide chain integrity and securing software program repositories.

The $150 million mobilization effort introduced in Could is an initiative that Behlendorf stated is about, “taking the circus on the street,” in an effort to assist present a concrete set of initiatives to safe open-source software program. 

“The massive theme all through the mobilization plan has not been how can we make open-source builders get extra severe, however it has been about how can we present up with assist?” Behlendorf stated. “How can we add to their present processes with higher tooling, paying for folks to point out up on initiatives and say we’re right here to assist in a method or one other.”

See also  Report: 60% of U.S. infosec professionals believe ransomware is as serious as terrorism

Key initiatives 

Over the course of the day, a number of audio system took the rostrum to element numerous OpenSSF related efforts to assist enhance open supply software program

One of the vital fundamental, but least well-understood facets of safety total is easy methods to truly correctly disclose a safety vulnerability. In a session throughout OpenSSF day, Anne Bertucio, senior program supervisor at Google, outlined finest practices for open-source builders in easy methods to responsibly disclose vulnerabilities. Bertucio pointed to the OpenSSF’s OSS Vulnerability Guide as a playbook that organizations can use to assist with the method.

Navin Srinivasan, safety engineer at Endor Labs outlined the OpenSSF Scorecard undertaking, which has its roots in initiatives that pre-date the creation of the OpenSSF. The scorecard undertaking provides open-source initiatives a ‘rating’ based mostly on adherence to finest practices for safety.

A associated undertaking is the Allstar Mission which was initially introduced again in August 2021. Jeff Mendoza, safety engineer at Google defined that whereas scorecard offers a rating, Allstar might help customers enhance the rating. Mendoza stated that Allstar operates as a GitHub utility that repeatedly checks to your safety finest practices on code repositories, and might allow customers to shortly remediate points.

Alpha Omega undertaking funds Python and Eclipse safety

One other key undertaking below OpenSSF is the Alpha-Omega provide chain safety effort which was began again in February.

Throughout OpenSSF Day, the OpenSSF introduced that through Alpha-Omega, $800,000 in funding goes to be offered to assist safe expertise initiatives from the Python Software program Basis and from the Eclipse Basis.

Python is without doubt one of the hottest open-source programming languages in use at present. The brand new funding will probably be used to supply help for devoted safety experience that can formalize finest practices throughout Python Software program Basis initiatives.

The Eclipse Basis develops software program improvement instruments, together with the Eclipse Built-in Developer Surroundings (IDE). Funding for Eclipse will probably be used to assist the group to implement provide chain finest practices for safety.

Moreover, the Google initiated Safe Open Supply Rewards (SOS.dev) undertaking will now be transferring below the auspices of the OpenSSF. SOS.dev is an initiative designed to assist reward builders for implementing safety finest practices in open supply software program initiatives.

See also  Keeper Security acquires Glyptodon to enhance privileged access management platform

Safety is the value of open-source innovation

The OpenSSF’s $150 million mobilization effort was motivated in no small half by the emergence of the open-source Log4j vulnerabilities that had been disclosed in December 2021. That incident helped to place renewed concentrate on the challenges of open supply safety.

Jamie Thomas, normal supervisor of technique and improvement at IBM commented that the Log4j incident was a catalyst for these concerned within the open-source business to determine easy methods to be extra proactive about safety. A problem for a lot of with the Log4 incident was that it was incumbent on finish customers in some instances to determine in the event that they had been weak after which patch. She said that finish customers shouldn’t have needed to fear about that and it’s up to people who construct and supply software program to assist help it.

“It’s our obligation to take the burden of safety and guarantee that the software program is designed with safety in thoughts,” Thomas stated.

Among the many many massive organizations that had been impacted by Log4j, was monetary big JPMoran Chase. Rao Kakkakula, director at JPMorgan Chase, commented that previously, his group might need probably had a knee jerk response to the Log4J incident and easily determined to only cease utilizing the open-source software program and construct one thing on their very own. That’s not what’s taking place now in 2022.

Kakkakula stated that executives inside JPMorgan Chase are actually asking how the corporate can higher help the open-source group to enhance safety.

“The pattern is altering to being extra supportive moderately than blaming folks,” Kakkakula stated.

JPMorgan’s want to assist enhance open-source safety isn’t based mostly on some altruistic purpose, however moderately a really sensible one. Kakkakula defined that there are over 53,000 builders at JPMorgan Chase. He famous that almost all functions at present make use of open supply software program to assist drive innovation ahead.

“To innovate sooner, open supply is the important thing for my part as I don’t wish to reinvent the wheel,” Kakkakula stated. “Then safety is the important thing to really enabling the expertise in order that we preserve the client belief intact.”

Source link

Tags: advancementsDetailseffortsopensourceOpenSSFsecurity
Previous Post

FlowForma Raises €4M in Funding

Next Post

Hitmarker partners with National Student Esports (NSE)

Next Post
Hitmarker partners with National Student Esports (NSE)

Hitmarker partners with National Student Esports (NSE)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Newsletter

Popular Stories

  • DeepFace - Most Popular Deep Face Recognition in 2022 (Guide)

    DeepFace – Most Popular Deep Face Recognition in 2022 (Guide)

    0 shares
    Share 0 Tweet 0
  • How To Set Up PS5 Remote Play On The Steam Deck

    0 shares
    Share 0 Tweet 0
  • Google’s PaLM AI Is Far Stranger Than Conscious

    0 shares
    Share 0 Tweet 0
  • Mirato’s mitigation planning feature allows users to uncover potential third-party risks

    0 shares
    Share 0 Tweet 0
  • Cyberint Raises $40M in Funding

    0 shares
    Share 0 Tweet 0

Security Jobs

View 115 Security Jobs at Tesla

View 165 Security Jobs at Nvidia

View 105 Security Jobs at Google

View 135 Security Jobs at Amamzon

View 131 Security Jobs at IBM

View 95 Security Jobs at Microsoft

View 205 Security Jobs at Meta

View 192 Security Jobs at Intel

Accounting and Finance Hub

Raised Seed, Series A, B, C Funding Round

Get a Free Insurance Quote

Try Our Accounting Service

AI EXPRESS

AI EXPRESS is a news site that covers the latest developments in Artificial Intelligence, Data Analytics, ML & DL, Algorithms, RPA, NLP, Robotics, Smart Homes & Cities, Cloud & Quantum Computing, AR & VR and Blockchains

Categories

  • AI
  • Ai videos
  • Apps
  • AR & VR
  • Blockchain
  • Cloud
  • Computer Vision
  • Crypto Currency
  • Data analytics
  • Esports
  • Gaming
  • Gaming Videos
  • Investment
  • IOT
  • Iot Videos
  • Low Code No Code
  • Machine Learning
  • NLP
  • Quantum Computing
  • Robotics
  • Robotics Videos
  • RPA
  • Security
  • Smart City
  • Smart Home

Quick Links

  • Reviews
  • Deals
  • Best
  • AI Jobs
  • AI Events
  • AI Directory
  • Industries

© 2021 Aiexpress.io - All rights reserved.

  • Contact
  • Privacy Policy
  • Terms & Conditions

No Result
View All Result
  • AI
  • ML
  • NLP
  • Vision
  • Robotics
  • RPA
  • Gaming
  • Investment
  • More
    • Data analytics
    • Apps
    • No Code
    • Cloud
    • Quantum Computing
    • Security
    • AR & VR
    • Esports
    • IOT
    • Smart Home
    • Smart City
    • Crypto Currency
    • Blockchain
    • Reviews
    • Video

© 2021 Aiexpress.io - All rights reserved.