For #opensource maintainers with projects spanning 20+ repos, it's often manual and time-consuming to manage repo configuration. We built a policy template in Minder to automate this—you can customize it and apply it to your repos for free: https://t.co/xSN2Xlu27D
Craig McLuckie from #Stacklok gives a keynote about navigating supply chain risk in a world of #AI assisted developers, LIVE at #ossummit.
View the schedule: https://t.co/8uAORdsF36
#opensource
@StackLokHQ booth is busy as always. Drop by tomorrow if in town. We are revealing a new project for software supply chain security + more minder goodness. I have not been this excited about a project since @projectsigstore came about. #OSSummit
AI and supply chain risk discussions are getting interesting at #ossummit!
@cmcluck talking about the need for work needed around provenance and attestation for Gen AI models
The Good, Bad and Ugly for GenAI by @cmcluck at #OSSummit
The Good: More productive maintainers
The Bad: New vulnerabilities and methods of exploitation
The ugly: Increasing pressure on communities
Path forward for #opensource producers and consumers
Since ChatGPT, “the number of hostile open source packages has gone through the roof” —@StackLokHQ’s @cmcluck. These hostile actors threaten to “undermine the trust in open source.” #OSSummit
(1/2) 👋 We made some big announcements today at the #OSSummit. Here's the first.
Today, we're introducing the OSS Trust Graph, a way to model trust in #opensource ecosystems. It maps the connections between open source contributors and projects, and, through our “proof-of-diligence” algorithm, uses that data to build an understanding of the relative safety and sustainability of those projects.
We think this Trust Graph can help in two ways:
1) Identifying malicious activity. We can’t say with confidence that the OSS Trust Graph would have uncovered the XZ vulnerability, but we believe it’s a step in the right direction. We know that the hostile actors’ introduction of many relatively unknown “sock puppet” accounts would have driven down the score of the project. While there would be a fair amount of activity, the introduction of relatively unknown individuals all contributing to the same project would lower the project’s score, providing a signal to the community.
2) Identifying open source projects that need support. Through changes in scoring, the OSS Trust Graph could help us understand when high-contributing maintainers leave a high-scoring and widely used project, leaving it vulnerable to being abandoned or to a hostile takeover. Likewise, it could help identify high-scoring projects with a low number of high-scoring maintainers that could benefit from additional support and funding.
Read more about this and sign up for private beta access here: https://t.co/5mGbTwbZmd
(2/2) Our second announcement: Minder Cloud!
Having high-quality intelligence about open source packages is only as useful as an organization’s or a community’s ability to drive policies that shape developer behavior. That’s why we launched the open source software security platform Minder last November, as a way to apply and continuously enforce policies across the software delivery lifecycle.
Today, we are launching Minder Cloud, a fully managed version of Minder that makes it easier for open source developers and communities to set up and enforce policies to help them produce safer, more sustainable software.
To that end, we have committed to making Minder Cloud free forever for use on public repositories.
Read more and get started with Minder Cloud here: https://t.co/kFo2QLNYJB
Busy day at @StackLokHQ , we also released Minder Cloud today. Craft custom policies for remediation at scale. The GitHub provider implementation is in place with a UI to compliment the CLI. https://t.co/Az8gq3qYad
We (@StackLokHQ) have released details of our Proof-of-Diligence algorithm and Graph. Very curious to see what others make of this. We have a private beta starting next week where we expose the API/UI for others try: https://t.co/zazECYu4qw
We're at #OSSummit this week! Stop by our booth in the Solutions Showcase to say hi and catch a demo of new Minder capabilities. (And grab some new socks 🙂 )
And don't miss @cmcluck 's keynote on Weds at 10:20; he'll be talking about AI security and announcing some new capabilities to help #opensource communities detect and prevent supply chain attacks. (Details here: https://t.co/ChHiidByER)
Trusty ingests and analyzes data on thousands of open source packages to calculate supply chain risk scores. We started with a monolithic architecture, processing package data in sequence based on a state manager—but hit challenges as Trusty expanded.
Staff Engineer @yrobla recently led our migration to an event-driven, microservices-based architecture, and explains the outcomes (and challenges) of moving to an @awscloud SNS + SQS stack for large-scale data processing. Trusty now hooks in to the open source Feeds project from @openssf for package updates. https://t.co/RqsoO6Chp6
Today at 9 AM PT! See how Minder OSS can analyze new packages introduced in a developer's PR for their supply chain risk heuristics (via https://t.co/6n6WfSok37) and active vulnerabilities (via https://t.co/aJ4UfHDIsv, from @GoogleOSS). https://t.co/I3r4OXGgaw