Тёмный

Moving past the CVE back-and-forth 

Tidelift
Подписаться 214
Просмотров 28
50% 1

In his Upstream session, James Berthoty CEO of Latio Tech provides an overview of what the problem is with submitting CVEs to GitHub issues-why it's frustrating for compliance teams and maintainers both. In this clip, he explains how, to move past the CVE back-and-forth, we need to pay open source maintainers and build a better working relationship with them.
Watch the full talk here: explore.tideli...
Transcript:
So what are some better ways forward here that we can make more sense of this CVE back and forth that happens? The first, which is something I'm always advocating for, is that we call open source maintainers vendors when we treat them like vendors, and we publish CVEs and expect them to fix them as though they're contractors. And so we should actually pay them and have some kind of contract in place as though they are vendors or contractors to establish the relationship ahead of time. It's extremely unfair how we expect them to patch CVEs without having any formal relationship to us.

Опубликовано:

 

21 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
The Most Legendary Programmers Of All Time
11:49
Просмотров 585 тыс.
Open Source Explained
6:11
Просмотров 67 тыс.
DIY Pump Solutions
00:18
Просмотров 1,3 млн
Борщ в стиле высокой кухни!
00:57
Don't Contribute to Open Source
9:55
Просмотров 237 тыс.
Don't use these services for your SaaS
6:45
Просмотров 29 тыс.
Don't Use ChatGPT Until You Watch This Video
13:40
Просмотров 1,7 млн