Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ How Python's New Security Developer Hopes To Help All Software Supply Chains

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š How Python's New Security Developer Hopes To Help All Software Supply Chains


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: developers.slashdot.org

Long-time Slashdot reader destinyland writes: The Linux Foundation recently funded a new "security developer in residence" position for Python. (It's funded through the Linux Foundation's own "Open Software Security foundation", which has a stated mission of partnering with open source project maintainers "to systematically find new, as-yet-undiscovered vulnerabilities in open source code, and get them fixed to improve global software supply chain security.") The position went to the lead maintainer for the HTTP client library urllib3, the most downloaded package on the Python Package Index with over 10 billion downloads. But he hopes to create a ripple effect by demonstrating the impact of security investments in critical communities โ€” ultimately instigating a wave of improvements to all software supply chains. (And he's also documenting everything for easy replication by other communities...) So far he's improved the security of Python's release processes with signature audits and security-hardening automation. But he also learned that CVE numbers were being assigned to newly-discovered vulnerabilities by the National Cyber Security Division of the America's Department of Homeland Security โ€” often without talking to anyone at the Python project. So by August he'd gotten the Python Software Foundation authorized as a CVE Numbering Authority, which should lead to more detailed advisories (including remediation information), now reviewed and approved by the responsible security response teams. "The Python Software wants to help other Open Source organizations, and will be sharing lessons learned," he writes in a blog post. And he now says he's already been communicating with the Curl program about his experiences to help them take the same step, and even authored a guide to the process for other open source projects.

Read more of this story at Slashdot.

...



๐Ÿ“Œ How Python's New Security Developer Hopes To Help All Software Supply Chains


๐Ÿ“ˆ 77.57 Punkte

๐Ÿ“Œ How Python's New Security Developer Hopes To Help All Software Supply Chains


๐Ÿ“ˆ 77.57 Punkte

๐Ÿ“Œ Synopsys hopes to mitigate upstream risks in software supply chains with new SCA tool


๐Ÿ“ˆ 49.7 Punkte

๐Ÿ“Œ Integrating Software Supply Chains and DevOps: Tips for Effectively Reconciling Supply Chain Management and DevOps


๐Ÿ“ˆ 38.69 Punkte

๐Ÿ“Œ BluBracket enhances its code security solution to help enterprises protect software supply chains


๐Ÿ“ˆ 38.25 Punkte

๐Ÿ“Œ Arnica raises $7 million to protect software supply chains without harming developer velocity


๐Ÿ“ˆ 36.78 Punkte

๐Ÿ“Œ Many Nations Pin Climate Hopes On China, India As Hopes For Trump Fade


๐Ÿ“ˆ 34.58 Punkte

๐Ÿ“Œ Security Highlights: New CWE Rankings, Software Supply Chains, and Side-Channel Attacks


๐Ÿ“ˆ 34.34 Punkte

๐Ÿ“Œ Major Hotel Chainsโ€™ Security Systems Exposed In Pyramid Hotel Group Data Leak (Marriott, Plaza, other chains may be impacted)


๐Ÿ“ˆ 33.82 Punkte

๐Ÿ“Œ A new Linux Foundation open source signing tool could make secure software supply chains universal


๐Ÿ“ˆ 32.41 Punkte

๐Ÿ“Œ Yearsโ€™ Old Unpatched Python Vulnerability Leaves Global Supply Chains at Risk


๐Ÿ“ˆ 31.66 Punkte

๐Ÿ“Œ Securing Software Supply Chains - Application Security Weekly #61


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ DevSecOps & Software Supply Chains, Microsoft - Application Security Weekly #64


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ Securing Software Supply Chains โ€“ Application Security Weekly #61


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ DevSecOps & Software Supply Chains, Microsoft โ€“ Application Security Weekly #64


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ Cyberrisiken fรผr Software Supply Chains - Security-Insider


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ Investors Bet on Ox Security to Guard Software Supply Chains


๐Ÿ“ˆ 31.41 Punkte

๐Ÿ“Œ Immer mehr Angriffe auf Software-Supply-Chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Cyberrisiken fรผr Software Supply Chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ hackers see green field opportunities in vulnerable software supply chains.


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ 82% of CIOs believe their software supply chains are vulnerable


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Veracode platform enhancements improve developersโ€™ ability to secure software supply chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Software supply chains at risk: The account takeover threat


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Endor Labs emerges from stealth with $25 million to protect software supply chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ #RSAC: Securing Software Supply Chains Requires Outside-the-Box Thinking


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Aqua identifiziert anfรคllige Software-Supply-Chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Juniper Research Study Reveals Staggering Cost of Vulnerable Software Supply Chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Industry piles in on North Korea for sustained rampage on software supply chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Google Announces GUAC Open-Source Project On Software Supply Chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Space X-Vorfall zeigt: Software Supply Chains weiter gefรคhrdet


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ GitGuardian Honeytoken helps companies secure their software supply chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ Tidelift has been awarded a $3.5 million contract to secure software supply chains


๐Ÿ“ˆ 29.49 Punkte

๐Ÿ“Œ From Fire Victims To Supply Chains, Trulioo Finds New Uses For KYC


๐Ÿ“ˆ 28.08 Punkte

๐Ÿ“Œ Dell has established new ways to protect its PC and server supply chains


๐Ÿ“ˆ 28.08 Punkte











matomo