Главная
Study mode:
on
1
Introduction
2
Strategy Doc
3
Awareness
4
Bill
5
Is awareness a problem
6
Adoption
7
Best Practices
8
Scorecard
9
Target Audience
10
Education Best Practices
11
Spread Awareness
12
Reference S2C2F
13
Education
14
Security Tools
Description:
Explore the S2C2F SIG's efforts to enhance open source software dependency security in this 48-minute conference talk. Delve into the group's work within the OpenSSF's Supply Chain Integrity Working Group, focusing on the development and improvement of the S2C2F guide. Learn about the guide's two-part structure, including solution-agnostic practices and a maturity model-based implementation guide. Discover strategies for raising awareness, adoption challenges, and best practices for organizations seeking to bolster their software supply chain security. Gain insights into the Scorecard project, target audience considerations, and educational approaches to promote secure OSS consumption. Examine the importance of referencing S2C2F and implementing security tools in the development process.

Secure Software Supply Chain Framework (S2C2F) Guide - OpenSSF SIG Meeting

OpenSSF
Add to list
0:00 / 0:00