Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Minimise the risk of open source usage by using...
Search
Juan Antonio Osorio
March 15, 2024
Technology
0
38
Minimise the risk of open source usage by using healthy open source projects
Juan Antonio Osorio
March 15, 2024
Tweet
Share
More Decks by Juan Antonio Osorio
See All by Juan Antonio Osorio
Fortify & Forget
jaormx
0
57
Other Decks in Technology
See All in Technology
茨城の思い出を振り返る ~CDKのセキュリティを添えて~ / 20260201 Mitsutoshi Matsuo
shift_evolve
PRO
1
370
量子クラウドサービスの裏側 〜Deep Dive into OQTOPUS〜
oqtopus
0
140
Context Engineeringの取り組み
nutslove
0
380
【Ubie】AIを活用した広告アセット「爆速」生成事例 | AI_Ops_Community_Vol.2
yoshiki_0316
1
120
We Built for Predictability; The Workloads Didn’t Care
stahnma
0
150
Agent Skils
dip_tech
PRO
0
120
SRE Enabling戦記 - 急成長する組織にSREを浸透させる戦いの歴史
markie1009
0
160
Ruby版 JSXのRuxが気になる
sansantech
PRO
0
160
AWS Network Firewall Proxyを触ってみた
nagisa53
1
240
顧客との商談議事録をみんなで読んで顧客解像度を上げよう
shibayu36
0
280
今こそ学びたいKubernetesネットワーク ~CNIが繋ぐNWとプラットフォームの「フラッと」な対話
logica0419
3
290
コミュニティが変えるキャリアの地平線:コロナ禍新卒入社のエンジニアがAWSコミュニティで見つけた成長の羅針盤
kentosuzuki
0
130
Featured
See All Featured
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1.1k
RailsConf 2023
tenderlove
30
1.3k
Product Roadmaps are Hard
iamctodd
PRO
55
12k
How to make the Groovebox
asonas
2
1.9k
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
830
Balancing Empowerment & Direction
lara
5
890
Fireside Chat
paigeccino
41
3.8k
Ecommerce SEO: The Keys for Success Now & Beyond - #SERPConf2024
aleyda
1
1.8k
Code Review Best Practice
trishagee
74
20k
Embracing the Ebb and Flow
colly
88
5k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
141
34k
16th Malabo Montpellier Forum Presentation
akademiya2063
PRO
0
52
Transcript
A rant on open source project vetting Minimise the risk
of open source usage by using healthy open source projects
Who am I? Juan Antonio “Ozz” Osorio Staff Security Beard
2 ©Stacklok, Inc 2024 Mexican living in Finland Talk to me about: • Supply chain security • Vulnerability management • Cloud security • Craft beer • Running • Heavy metal
Who are we? Stacklok est. May 2023 3 ©Stacklok, Inc
2024 We're passionate about making open source software safer. We help you • Build safer software • Make safer dependency choices • Keep your software pipelines secure We aim to simplify supply chain security
Open Source is everywhere • It’s in your infrastructure •
You’re third party providers use it • It’s in your dependencies • It’s the software you build • It even runs on your work or personal machine 4 ©Stacklok, Inc 2024 We’ve won!
Who has a say about open source in your organization?
5 ©Stacklok, Inc 2024 Question
Make an informed decision on what open source project(s) to
allow and promote within your organization 6 ©Stacklok, Inc 2024 The challenge
Problem solved… Right? 7 ©Stacklok, Inc 2024 Just use GitHub
stars…
8 ©Stacklok, Inc 2024 … Wait a minute…
9 ©Stacklok, Inc 2024 Just Google it!
10 ©Stacklok, Inc 2024 … or not
11 ©Stacklok, Inc 2024 … or not * Side note:
ChatGPT actually returned better results
12 ©Stacklok, Inc 2024 … or not * Side note:
ChatGPT actually returned better results… NO! Don’t rely on it to make these decisions for you…
13 ©Stacklok, Inc 2024 … or not * Side note:
ChatGPT actually returned better results… NO! Don’t rely on it to make these decisions for you… yet
14 ©Stacklok, Inc 2024 Alright… But, stay away from CVE’s
right?
Are CVEs a bad thing? 15 ©Stacklok, Inc 2024 Should
I be scared?
16 ©Stacklok, Inc 2024 Tell me already!
Things to look for • Good habits/code hygiene • Active
development • Developers we trust • Responsible disclosure encouraged • CVE and SCA clear … Not talking about licenses today as your mileage may vary 17 ©Stacklok, Inc 2024 Tell me already!
18 ©Stacklok, Inc 2024 Hygiene
19 ©Stacklok, Inc 2024 Active Development
20 ©Stacklok, Inc 2024 Developers we trust
21 ©Stacklok, Inc 2024 Responsible disclosure encouraged
22 ©Stacklok, Inc 2024 CVE and SCA clear
23 ©Stacklok, Inc 2024 Cool! Are we done yet?
Supply Chain Security • Do you know where your container/package/artifact
comes from? • How was it built? • Do they follow best practices? • How do I know what was included in the build? • How do I know that it’s the right one? 24 ©Stacklok, Inc 2024 OK… Now what?
Supply Chain Security 25 ©Stacklok, Inc 2024 Open Source to
the rescue!
Supply Chain Security 26 ©Stacklok, Inc 2024 Where do I
start?
Shameless self-promotion! Minder Trusty 27 ©Stacklok, Inc 2024
We all love numbers!! 28 ©Stacklok, Inc 2024 Trusty
We all love numbers!! 29 ©Stacklok, Inc 2024 Trusty
… Suspicious… 30 ©Stacklok, Inc 2024 Run!
Minder policy as code 31 ©Stacklok, Inc 2024 Minder
Minder policy as code 32 ©Stacklok, Inc 2024 Enforce on
the spot
Fix suggestion in the PR 33 ©Stacklok, Inc 2024 Vulnerability
scanning
Information straight in GitHub 34 ©Stacklok, Inc 2024 Trusty score
scanning
Minder is OSS • Try it out! ◦ We have
a running production instance • Check it out! ◦ https://github.com/stacklok/minder • Give us feedback! ◦ You can issue a GitHub issue or even talk to us on Discord • Document or code! ◦ We’re happy to review 35 ©Stacklok, Inc 2024 How you can help!
Thank you! Minder in GitHub Join us in Discord! Try
out Trusty! We’re hiring! 36 ©Stacklok, Inc 2024