TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

OpenSSF: Open Source Security Foundation

128 点作者 PatrolX将近 5 年前

3 条评论

hansjorg将近 5 年前
Maybe this should link to <a href="https:&#x2F;&#x2F;openssf.org" rel="nofollow">https:&#x2F;&#x2F;openssf.org</a> or the press release (<a href="https:&#x2F;&#x2F;openssf.org&#x2F;press-release&#x2F;2020&#x2F;08&#x2F;03&#x2F;technology-and-enterprise-leaders-combine-efforts-to-improve-open-source-security&#x2F;" rel="nofollow">https:&#x2F;&#x2F;openssf.org&#x2F;press-release&#x2F;2020&#x2F;08&#x2F;03&#x2F;technology-and-...</a>) rather than to the GitHub project?<p>Highlights from the FAQ:<p>&gt; OpenSSF is focused on improving the security of open source software (OSS) by building a broader community with targeted initiatives and best practices. It will start with a focus on metrics, tooling, best practices, developer identity validation and vulnerability disclosures best practices.<p>&gt; OpenSSF will be supported by Linux Foundation membership dues with targeted organization contributions to support initiatives<p>&gt; The founding members are GitHub, Google, IBM, JPMorgan Chase, Microsoft, NCC Group, OWASP Foundation and Red Hat, among others.
评论 #24048042 未加载
评论 #24044615 未加载
TACIXAT将近 5 年前
It is really interesting that major open source initiatives are now being ran by corporations. I feel this will be open source in the sense that it is being developed in the open, but not in the sense that they will foster an environment of community contribution.<p>For example, the working group for vulnerability disclosure includes a lot of corporate players, and from what I can tell, not a single security researcher. Only one side of the disclosure process is represented in that working group.<p>Realizing how allergic major companies are to GPL code really creates some skepticism when they speak about embracing open source.
评论 #24047574 未加载
评论 #24046623 未加载
评论 #24045334 未加载
评论 #24047379 未加载
评论 #24046662 未加载
评论 #24047867 未加载
评论 #24045340 未加载
mintyc将近 5 年前
Such a shame these initiatives don&#x27;t build on existing standards working groups but go away and reinvent a wheel instead.<p>Take a look for instance at ETSI TC Cyber, or ETSI NFV Sec.<p>Even more available in specific domains, such as intelligent transport systems (ISG WG5)<p>Let&#x27;s have one more standard promoting another agenda and set of priorities.<p>Open standards should also promote consolidated standards.
评论 #24050661 未加载
评论 #24048098 未加载
评论 #24047041 未加载