Skip to content

Vulnerability management for open software development (OSCON pass required)

Photo of Jamie Donaho
Hosted By
Jamie D.
Vulnerability management for open software development (OSCON pass required)

Details

Vulnerability management for open software development

Prerequisite Knowledge

Familiarity with defect handling and development in open/free community software will enhance the experience, but is not strictly necessary.

Description

The vulnerability management team for the OpenStack project handles hundreds of incoming reports of potential security vulnerabilities, and publishes dozens of advisories every year. Reconciling reception, embargo, and coordinated disclosure of vulnerability reports, in otherwise entirely open and community-developed software, is no small feat.

In this talk I’ll discuss the published vulnerability management processes followed by the OpenStack project and the supporting tooling we employ. I’ll also explain the conflict between open communication and coordinated disclosure, a balance with which many free software projects struggle, and how we’ve managed to maintain it without compromising our community ideals.

Jeremy Stanley OpenStack Foundation

A long-time computer hobbyist and technology generalist, Jeremy has worked as a Unix and GNU/Linux sysadmin for more than two decades focusing on information security, internet services, and datacenter automation. He’s a root member of the OpenStack project infrastructure team, and serves on the OpenStack vulnerability management team. Living on a small island in the Atlantic, in his spare time he writes free software, hacks on open hardware projects and embedded platforms, restores old video game systems, and enjoys articles on math theory and cosmology.

More details here:

http://www.oscon.com/open-source-2015/public/schedule/detail/41753

Photo of Portland Open Infrastructure group
Portland Open Infrastructure
See more events
Oregon Convention Center
777 NE MLK Blvd. Exhibit Hall D · Portland, OR