Тёмный

Open source maintainers are not contracted vendors 

Tidelift
Подписаться 214
Просмотров 34
50% 1

In his Upstream session, James Berthoty CEO of Latio Tech provides an overview of what the problem is with submitting CVEs to GitHub issues-why it's frustrating for compliance teams and maintainers both. In this clip, he emphasizes that open source maintainers, who are often volunteers, are not contracted vendors.
Watch the full talk here: explore.tideli...
Transcript:
Now vendor dependencies are where these CVEs, by default, have to fall, even though open source maintainers don't have a contract in place to make them a vendor in a formal sense. Nonetheless, that's how they have to be treated, because there's really no other options for what to do with these vulnerabilities when they're discovered. And so when you have a vendor dependency, your guidelines are forcing you to, you're supposed to check in with the vendor upstream every 30 days for either them to confirm that it's a false positive or for them to give you their timeline for remediation. And so that is the process for what compliance has and what you can see is they if they are following from a strict compliance viewpoint here, the number of options they have are very limited for how to report these findings to a vendor.

Опубликовано:

 

21 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
The Most Legendary Programmers Of All Time
11:49
Просмотров 585 тыс.
Немного заблудился 😂
00:16
Просмотров 300 тыс.
3D Gaussian Splatting! - Computerphile
17:40
Просмотров 142 тыс.
USA B2 BOMBER RAID IN YEMEN: MESSAGE FOR IRAN?
15:02
Просмотров 360 тыс.
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
The Rise of India's Private Space Firms | Momentum
24:02