OpenSourceFellows / open-source-mentorship

Inspiring the next generation of open source contributors and maintainers
https://www.notion.so/programequity/ProgramEquity-Open-Source-Fellows-5f4dfc06109842779b81e8166c056334
Creative Commons Zero v1.0 Universal
16 stars 1 forks source link

[Workshop] Securing Your Open Source Workflow with GitHub Security Lab, Sonatype and Snyk | March 16th, 2023 #14

Open marcosbergami opened 1 year ago

marcosbergami commented 1 year ago

For Speaker(s):

Speaker info

Liran Tal

Name: Liran Tal GitHub Handle: @lirantal Bio:

Liran Tal is an award-winning software developer, security researcher, and open source champion in the JavaScript community. He's an internationally recognized GitHub Star, acknowledged for his open source advocacy, and has received the OpenJS Foundation's Pathfinder for Security for his work on Node.js security. His contributions to developer security education include leading OWASP projects, building supply chain security tools, participation in CNCF and OpenSSF initiatives, and authoring books such as O'Reilly's Serverless Security. He leads the developer advocacy team at Snyk.io and is on a mission to empower developers with better application security skills.

LinkedIn: https://www.linkedin.com/in/talliran/

Speaker Name

Name: GitHub Handle: Bio: LinkedIn:

Workshop Links

Zoom Link: https://github.zoom.us/j/97013759503?pwd=aDd5NmNKQTNsbGlLQWhuSm4vVEFGdz09 Eventbrite link: https://www.eventbrite.com/e/securing-your-open-source-workflow-with-github-security-lab-and-snyk-tickets-532730861347?aff=ebdsoporgprofile Notion Card Link: https://programequity.notion.site/Securing-Your-Open-Source-Workflow-with-GitHub-Security-Lab-and-Snyk-36173ea5919c4922be0ac11f16fff56f

Presentation Overview

Presentation Materials

Operations


For Organizers:

Pre-workshop

lirantal commented 1 year ago

Hi folks,

I'm sharing here in a more broad audience some ideas for topics

Open source ecosystem

How security research powers health of supply chain

What are CVEs

Methods for publicly sharing information on cybersecurity vulnerabilities and exposures

Workflows for the ecosystem

How you can implement secret scanning, code scanning, and dependencies

Demo

Resolving a security advisory

lirantal commented 1 year ago

Also, I see we have draft slide deck worked out here if that's the relevant one still to use? if so, happy if you can add me to edit :)

marcosbergami commented 1 year ago

Also, I see we have draft slide deck worked out here if that's the relevant one still to use? if so, happy if you can add me to edit :)

Hey @therzka, can you please confirm if the slide deck noted in the Notion page is still relevant to use in this workshop ? Thank you!

therzka commented 1 year ago

@marcosbergami I don't have permission to share that one right now and there's obviously not much there anyway :) feel free to start a new one and share the link here.

@lirantal I love the topics you've outlined above... leaning towards high level is better but feel free to run with any/all of them. Definitely like the idea of touching on what CVEs and bug bounties are, how CVEs are discussed publicly.

also, hi Twitter friend!

lirantal commented 1 year ago

Hi there Tali 🤗 and thanks for the feedback. Looks like we're on track. Let's get a slide deck shared and we can pour some content into it.