Artwork

Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Jack Cable of CISA and Zach Steindler of GitHub Dig Into Package Repository Security

23:44
 
Share
 

Manage episode 452000935 series 3564832
Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

CRob discusses package repository security with two people who know a lot about the topic. Zach Steindler is a principal engineer at Github, a member of the OpenSSF TAC and co-chairs the OpenSSF Security Packages Repository Working Group. Jack Cable is a senior technical advisor at CISA. Earlier this year, Zach and Jack published a helpful guide of best practices called “Principles for Package Repository Security.”

  • 00:48 - Jack and Zach share their backgrounds
  • 02:59 - What package repositories are and why they’re important to open source users
  • 04:17 - The positive impact package security has on downstream users
  • 07:06 - Jack and Zach offer insight into the "Prinicples for Package Repository Security" document
  • 11:18 - Future endeavors of the Securing Software Repositories Working Group
  • 17:32 - Jack and Zach answer CRob’s rapid-fire questions
  • 19:31 - Advice for those entering the industry
  • 21:28 - Jack and Zach share their calls to action

Episode links:

  continue reading

29 episodes

Artwork
iconShare
 
Manage episode 452000935 series 3564832
Content provided by OpenSSF. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by OpenSSF or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

CRob discusses package repository security with two people who know a lot about the topic. Zach Steindler is a principal engineer at Github, a member of the OpenSSF TAC and co-chairs the OpenSSF Security Packages Repository Working Group. Jack Cable is a senior technical advisor at CISA. Earlier this year, Zach and Jack published a helpful guide of best practices called “Principles for Package Repository Security.”

  • 00:48 - Jack and Zach share their backgrounds
  • 02:59 - What package repositories are and why they’re important to open source users
  • 04:17 - The positive impact package security has on downstream users
  • 07:06 - Jack and Zach offer insight into the "Prinicples for Package Repository Security" document
  • 11:18 - Future endeavors of the Securing Software Repositories Working Group
  • 17:32 - Jack and Zach answer CRob’s rapid-fire questions
  • 19:31 - Advice for those entering the industry
  • 21:28 - Jack and Zach share their calls to action

Episode links:

  continue reading

29 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play