Note: If you want to access the links in the slides, please use the Google Slides version .
Overview
Modern IT systems heavily depend on OSS, and library development is no exception. While OSS offers benefits such as cost reduction and rapid development, vulnerabilities can have wide-reaching impacts. Particularly in library development, the security measures of dependent OSS are crucial as they affect many applications.
Security measures in OSS projects are also a vital indicator of the project's health. Based on the security improvements implemented in my OSS library (ts-graphviz), I will introduce several initiatives promoted by the Open Source Security Foundation (OpenSSF).
Remarks
These slides were used in the LT at the "Nextbeat Tech Bar: First Discussion on Library Development" held on May 24, 2024. The original presentation was conducted in Japanese, and these slides have been translated into English.