Enforcing the pyramid of Open Source

The well-known log4j security vulnerability of December 2021 triggered a lot of renewed discussions around software supply chain security, and sometimes it has also been said to be an Open Source related issue.
This was not the first software component to have a serious security flaw, and it will not be the last.
What can we do about it?
This is the 10,000 dollar question that is really hard to answer. In this post I hope to help putting some light on to why it is such a hard problem. This comes from my view as an Open Source author and contributor since almost three decades now.
In this post I’m going to talk about security as in how we make our products have less bugs in the code we write and land on purpose. There is also a lot to be said about infrastructure problems such as consumers not verifying dependencies so that when malicious actors purposely destroy a component, users of that don’t notice the problem or supply chain security issues that risk letting bad actors insert malicious code into components. But those are not covered in this blog post!
-
- Login or register to post comments
Printer-friendly version
- 1530 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
- June 2012 (259)
- May 2012 (198)
- April 2012 (227)
- March 2012 (209)
- February 2012 (219)
- January 2012 (406)
- December 2011 (328)
- November 2011 (424)
- October 2011 (315)
- September 2011 (433)
- August 2011 (510)
- July 2011 (518)
- June 2011 (570)
- May 2011 (566)
- April 2011 (503)
- March 2011 (621)
- February 2011 (555)
- January 2011 (558)
- December 2010 (609)
- November 2010 (635)
- October 2010 (600)
- September 2010 (618)
- August 2010 (598)
- July 2010 (605)
- June 2010 (603)
- May 2010 (659)
- April 2010 (653)
- March 2010 (658)
- February 2010 (653)
- January 2010 (647)
Recent comments
7 weeks 1 day ago
7 weeks 1 day ago
7 weeks 1 day ago
7 weeks 2 days ago
7 weeks 2 days ago
7 weeks 2 days ago
7 weeks 2 days ago
7 weeks 2 days ago
7 weeks 2 days ago
7 weeks 2 days ago