TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OpenSSF: Open Source Security Foundation

128 pointsby PatrolXalmost 5 years ago

3 comments

hansjorgalmost 5 years ago
Maybe this should link to <a href="https:&#x2F;&#x2F;openssf.org" rel="nofollow">https:&#x2F;&#x2F;openssf.org</a> or the press release (<a href="https:&#x2F;&#x2F;openssf.org&#x2F;press-release&#x2F;2020&#x2F;08&#x2F;03&#x2F;technology-and-enterprise-leaders-combine-efforts-to-improve-open-source-security&#x2F;" rel="nofollow">https:&#x2F;&#x2F;openssf.org&#x2F;press-release&#x2F;2020&#x2F;08&#x2F;03&#x2F;technology-and-...</a>) rather than to the GitHub project?<p>Highlights from the FAQ:<p>&gt; OpenSSF is focused on improving the security of open source software (OSS) by building a broader community with targeted initiatives and best practices. It will start with a focus on metrics, tooling, best practices, developer identity validation and vulnerability disclosures best practices.<p>&gt; OpenSSF will be supported by Linux Foundation membership dues with targeted organization contributions to support initiatives<p>&gt; The founding members are GitHub, Google, IBM, JPMorgan Chase, Microsoft, NCC Group, OWASP Foundation and Red Hat, among others.
评论 #24048042 未加载
评论 #24044615 未加载
TACIXATalmost 5 years ago
It is really interesting that major open source initiatives are now being ran by corporations. I feel this will be open source in the sense that it is being developed in the open, but not in the sense that they will foster an environment of community contribution.<p>For example, the working group for vulnerability disclosure includes a lot of corporate players, and from what I can tell, not a single security researcher. Only one side of the disclosure process is represented in that working group.<p>Realizing how allergic major companies are to GPL code really creates some skepticism when they speak about embracing open source.
评论 #24047574 未加载
评论 #24046623 未加载
评论 #24045334 未加载
评论 #24047379 未加载
评论 #24046662 未加载
评论 #24047867 未加载
评论 #24045340 未加载
mintycalmost 5 years ago
Such a shame these initiatives don&#x27;t build on existing standards working groups but go away and reinvent a wheel instead.<p>Take a look for instance at ETSI TC Cyber, or ETSI NFV Sec.<p>Even more available in specific domains, such as intelligent transport systems (ISG WG5)<p>Let&#x27;s have one more standard promoting another agenda and set of priorities.<p>Open standards should also promote consolidated standards.
评论 #24050661 未加载
评论 #24048098 未加载
评论 #24047041 未加载