113 subscribers
Player FM uygulamasıyla çevrimdışı Player FM !
Dinlemeye Değer Podcast'ler
SPONSOR


OpenJS Foundation’s Leader Details the Threats to Open Source
Manage episode 436827871 series 2574278
After the XZ Utils backdoor vulnerability was uncovered in March, the OpenJS Foundation saw a surge in inquiries from potential open source JavaScript contributors. Robin Ginn, executive director of the foundation, noted that volunteer-led JavaScript communities often face challenges in managing these contributions. The discovery that a single contributor, "Jia Tan," planted the backdoor heightened vigilance, especially when new contributors requested admin privileges. Ginn emphasized that trust is not synonymous with security, especially in open source projects where maintainers must be vigilant about who can access their repositories.
The XZ vulnerability highlighted broader concerns about the security of open source software, particularly in projects with only a single maintainer. Despite receiving a significant grant from Germany's Sovereign Tech Fund, the foundation remains under-resourced, with just two full-time staffers supporting 35 projects. Ginn urged companies that rely on open source software to invest in it by hiring maintainers, ensuring these critical projects are properly supported.
Learn more from The New Stack about open source vulnerability
Linux xz Backdoor Damage Could Be Greater Than Feared
Unzipping the XZ Backdoor and Its Lessons for Open Source
Linux xz and the Great Flaws in Open Source
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
301 bölüm
Manage episode 436827871 series 2574278
After the XZ Utils backdoor vulnerability was uncovered in March, the OpenJS Foundation saw a surge in inquiries from potential open source JavaScript contributors. Robin Ginn, executive director of the foundation, noted that volunteer-led JavaScript communities often face challenges in managing these contributions. The discovery that a single contributor, "Jia Tan," planted the backdoor heightened vigilance, especially when new contributors requested admin privileges. Ginn emphasized that trust is not synonymous with security, especially in open source projects where maintainers must be vigilant about who can access their repositories.
The XZ vulnerability highlighted broader concerns about the security of open source software, particularly in projects with only a single maintainer. Despite receiving a significant grant from Germany's Sovereign Tech Fund, the foundation remains under-resourced, with just two full-time staffers supporting 35 projects. Ginn urged companies that rely on open source software to invest in it by hiring maintainers, ensuring these critical projects are properly supported.
Learn more from The New Stack about open source vulnerability
Linux xz Backdoor Damage Could Be Greater Than Feared
Unzipping the XZ Backdoor and Its Lessons for Open Source
Linux xz and the Great Flaws in Open Source
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
301 bölüm
Tüm bölümler
×
1 Kong’s AI Gateway Aims to Make Building with AI Easier 21:05

1 What’s the Future of Platform Engineering? 26:44

1 AI Agents are Dumb Robots, Calling LLMs 28:31

1 Goodbye SaaS, Hello AI Agents 30:02

1 How Generative AI Is Reshaping the SDLC 21:42

1 OAuth Works for AI Agents but Scaling is Another Question 25:36

1 LLMs and AI Agents Evolving Like Programming Languages 28:08

1 Writing Code About Your Infrastructure? That's a Losing Race 31:21

1 OpenTelemetry: What’s New with the 2nd Biggest CNCF Project? 30:14

1 What’s Driving the Rising Cost of Observability? 24:55

1 How Oracle Is Meeting the Infrastructure Needs of AI 27:28

1 Arm: See a Demo About Migrating a x86-Based App to ARM64 21:28

1 Heroku Moved Twelve-Factor Apps to Open Source. What’s Next? 22:54

1 How Falco Brought Real-Time Observability to Infrastructure 19:27

1 How cert-manager Got to 500 Million Downloads a Month 23:18
Player FM'e Hoş Geldiniz!
Player FM şu anda sizin için internetteki yüksek kalitedeki podcast'leri arıyor. En iyi podcast uygulaması ve Android, iPhone ve internet üzerinde çalışıyor. Aboneliklerinizi cihazlar arasında eş zamanlamak için üye olun.