Upstream 2024: Panel: Life after the xz utils backdoor hack

Поделиться
HTML-код
  • Опубликовано: 4 июн 2024
  • In late March, we all dealt with yet another attack on a popular open source project; this time, in the Linux-level package used for file compression called xz utils.
    What was most sinister about this attack, though, was how deeply it impacted trust within the open source community. The attacker spent years engineering multiple sock puppet accounts to gain the trust of the volunteer xz utils maintainer.
    In this panel moderated by Tidelift VP of product Lauren Hanford, we’ll talk to Josh Bressers of Anchore; Jordan Harband, prolific Javascript maintainer; Rachel Stephens from RedMonk; Shaun Martin of BlackIce; and Terrence Fischer from Boeing to get a diverse mix of perspectives on how this changes the landscape of open source software supply chain security.
  • НаукаНаука

Комментарии •