Главная
Study mode:
on
1
Rules of Engagement for Forking a Dependency - Chris Swan, Atsign
Description:
Explore the decision-making process for forking dependencies in response to security vulnerabilities. Learn the rules of engagement used by Atsign when faced with CVE notifications and customer concerns about software bill of materials (SBOMs). Discover how to balance being a good community citizen while ensuring timely fixes for security issues. This 11-minute talk by Chris Swan from Atsign, presented at an OpenSSF event, provides valuable insights into when and how to fork dependencies responsibly in the face of unresolved vulnerabilities.

Rules of Engagement for Forking a Dependency

OpenSSF
Add to list
0:00 / 0:00