Chuyển sang chế độ ngoại tuyến với ứng dụng Player FM !
The Burden of Security in Software Maintenance
Manage episode 430544910 series 3446189
In this episode, John Kjell, Director of Open Source at TestifySec, discusses his involvement in various open source projects and the intricacies of maintaining such projects. John sheds light on his work with the CNCF and OpenSSF, and the impact of tools like Witness, Archivista, and SLSA. He outlines the challenges maintainers face, especially around security, and offers insights into balancing professional and personal responsibilities. John also explores the significance of community, inclusivity, and a secure developer identity in open source ecosystems.
00:00 Introduction and Guest Background
01:20 Maintainer Burnout and Security Challenges
04:41 Balancing Multiple Projects and Personal Life
07:15 Security Risks in Smaller Projects
10:13 Developer Identity and Reputation
19:37 Open Source Origin Story and Community Involvement
24:11 Optimism for the Future of Open Source Security
Enhancing Open Source Security: Introducing Siren by OpenSSF – Open Source Security Foundation
Security at Every Step: Why Software Supply Chains Are Critical
Guest: John Kjell is responsible for open source at TestifySec, a software supply chain security startup. He is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is an active contributor to CNCF's TAG Security and multiple projects within the OpenSSF. Before TestifySec, John was an engineering leader at VMware, helping to bring supply chain security features to the Tanzu Application Platform.100 tập
Manage episode 430544910 series 3446189
In this episode, John Kjell, Director of Open Source at TestifySec, discusses his involvement in various open source projects and the intricacies of maintaining such projects. John sheds light on his work with the CNCF and OpenSSF, and the impact of tools like Witness, Archivista, and SLSA. He outlines the challenges maintainers face, especially around security, and offers insights into balancing professional and personal responsibilities. John also explores the significance of community, inclusivity, and a secure developer identity in open source ecosystems.
00:00 Introduction and Guest Background
01:20 Maintainer Burnout and Security Challenges
04:41 Balancing Multiple Projects and Personal Life
07:15 Security Risks in Smaller Projects
10:13 Developer Identity and Reputation
19:37 Open Source Origin Story and Community Involvement
24:11 Optimism for the Future of Open Source Security
Enhancing Open Source Security: Introducing Siren by OpenSSF – Open Source Security Foundation
Security at Every Step: Why Software Supply Chains Are Critical
Guest: John Kjell is responsible for open source at TestifySec, a software supply chain security startup. He is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is an active contributor to CNCF's TAG Security and multiple projects within the OpenSSF. Before TestifySec, John was an engineering leader at VMware, helping to bring supply chain security features to the Tanzu Application Platform.100 tập
Tất cả các tập
×
1 Open Source Maintainership: The Highs, Lows, and Everything In Between 23:38

1 Understanding Observability with OpenTelemetry 21:50


1 Positioning and Strategy with Open Source 20:10

1 Balancing Act: Software Security and Developer Experience 25:32

1 Open Source and Public Policy: A Conversation with Deb Bryant 20:23

1 Canonical's Data Science Stack and AI's Open Future 19:34

1 From Kubernetes to Argo: Exploring the World of the Cloud Native End User 18:39

1 Breaking Down AI: Small Models, Big Impacts 20:44

1 Fostering Open Source Culture and Unlocking Innovation 27:54


1 The Open Source Path to Security and Privacy: Divvi Up and Let's Encrypt 22:02

Chào mừng bạn đến với Player FM!
Player FM đang quét trang web để tìm các podcast chất lượng cao cho bạn thưởng thức ngay bây giờ. Đây là ứng dụng podcast tốt nhất và hoạt động trên Android, iPhone và web. Đăng ký để đồng bộ các theo dõi trên tất cả thiết bị.