Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Assessing Open Source Software Projects in the Software Supply Chain Security

OpenSSF via YouTube

Overview

Learn about DoD software supply chain security practices in this 31-minute conference talk exploring techniques for evaluating open source software trustworthiness. Discover how the US Department of Defense's Unified Platform project develops methods to assess risk levels of open source software through analysis of project processes, policies, and practices. Gain insights into the integration of tools like MITRE's Hipcheck and OpenSSF Scorecard to support software approval processes. Understand how these evaluation techniques help address emerging Department of Defense guidance for open source software usage while providing concrete approaches for assessing both products and processes within the OSS ecosystem. The presentation demonstrates practical applications relevant to industrial, academic, and government institutions that rely heavily on open source software components.

Syllabus

Assessing Open Source Software Projects in the Software Supply... Scott Hissam & Joshua "CoCo" Crisp

Taught by

OpenSSF

Reviews

Start your review of Assessing Open Source Software Projects in the Software Supply Chain Security

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.