An Open Book Test: Securing Open Source Software With OpenSSF’s Scorecard — Stephen Augustus
ChariotSolutions ChariotSolutions
8.63K subscribers
78 views
1

 Published On Aug 1, 2023

Open source software is the backbone of the internet. It permeates our lives in ways that at times, are difficult to fully appreciate.

In recent years, pervasive software supply chain attacks have shined a bright light on the long-term sustainability of our open source ecosystems, including attention from enterprises and government agencies across the world.

So if you use, contribute to, or maintain open source software, how can you help?

Use OpenSSF Scorecard!

Scorecard is a tool to help analyze the security posture of open source projects.

In this talk, you’ll learn about how Scorecard works, how it can improve the projects you use, and how YOU can contribute to making our software ecosystem a more secure place.

__________________________________________________

About Stephen Augustus
Stephen is a Black engineering director and leader in open source communities.

He is the Head of Open Source at Cisco, working within the Strategy, Incubation, & Applications (SIA) organization.

For Kubernetes, he has co-founded transformational elements of the project, including the KEP (Kubernetes Enhancements Proposal) process, the Release Engineering subproject, and Working Group Naming. Stephen has also previously served as a chair for both SIG PM and SIG Azure.

He continues his work in Kubernetes as a Steering Committee member and a Chair for SIG Release.

Across the wider LF (Linux Foundation) ecosystem, Stephen has the pleasure of serving as a member of the OpenSSF Governing Board and the OpenAPI Initiative Business Governing Board.

Previously, he was a TODO Group Steering Committee member, a CNCF (Cloud Native Computing Foundation) TAG Contributor Strategy Chair, and one of the Program Chairs for KubeCon / CloudNativeCon, the cloud native community’s flagship conference.

He is a maintainer for the Scorecard and Dex projects, and a prolific contributor to CNCF projects, amongst the top 40 (as of writing) code/content committers, all-time.

In 2020, Stephen co-founded the Inclusive Naming Initiative, a cross-industry group dedicated to helping projects and companies make consistent, responsible choices to remove harmful language across codebases, standards, and documentation. He leads the Community/Open Source workstream and maintains the initiative’s infrastructure.

He has previously held positions at VMware (via Heptio), Red Hat, and CoreOS.

Stephen is based in New York City.

__________________________________________________

About the Conference
The Philly Emerging Technologies for the Enterprise (ETE) is the Mid-Atlantic's premier developer's conference. Entering its 17th year, we've brought world-class speakers — including some local favorites — to speak about leading-edge technologies being used today, and emerging technologies that will be important for attendees to know about in the near future.

__________________________________________________

About the Host
Philly ETE is hosted by Chariot Solutions, a software development consultancy.
For over 20 years, companies of all sizes and industries have
looked to Chariot as a partner to help them solve their toughest software challenges, and move their business forward.

Are you a business looking to build and manage software solutions optimized for your unique needs? We're here to help. We’ll apply our strategic, high-touch approach and extensive tech experience to solve your most complex business problems. Reach out today. Visit us at https://chariotsolutions.com/

__________________________________________________

Sponsored by Pinnacle 21
Employees at Pinnacle 21 do tech work that means something. Their software enables key transitions in the clinical trial data pipeline and streamlines regulatory approvals for drugs and medical devices, getting new treatments to patients faster. Pinnacle 21 supplies its SaaS platform to the US FDA, Japan’s PMDA, 24 of the top 25 biopharma firms, and many more biotechs. It ensures clinical trial data comply with the standards of both government agencies and trial sponsors. With strong product-market fit and an aggressive roadmap fueled by their 2021 acquisition by Certara (NASDAQ: CERT), the team is quickly becoming the one-stop data brokerage for the life sciences. Learn more: https://pinnacle21.com

Sponsored by Lutron
Lutron is the worldwide leader in lighting, automated shade and temperature controls, with headquarters in Lehigh Valley, Pennsylvania and engineering offices in Philadelphia, Boston, South Florida and Austin. We are a privately held manufacturing company with over 4000 design and product patents. We are at the forefront of innovating IoT products for smart homes and connected buildings. Learn more: https://www.lutron.com/en-US/pages/de...

show more

Share/Embed